# 5.0.0-okd-scos.ec.7
Created: 2026-08-17 06:01:24 +0000 UTC
Image Digest: `sha256:4da4dbf4575d84a880d66b63c45d8739e6646e92be94cca57d8f1254c75410d6`
Promoted from registry.ci.openshift.org/origin/release-scos:5.0.0-0.okd-scos-nightly-2026-08-14-163257
## Changes from 5.0.0-okd-scos.ec.5
### Components
* Kubectl upgraded from 1.35.2 to 1.36.2
* Kubernetes upgraded from 1.35.3 to 1.36.2
* Kubernetes Tests upgraded from 1.35.1 to 1.36.2
* CentOS Stream CoreOS 10 upgraded from 10.0.20260702-0 to 10.0.20260806-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| AzureClusterHostedDNSInstall
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| NewOLMPreflightPermissionChecks
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| RouteExternalCertificate
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| AWSDualStackInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| AdditionalStorageConfig
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| ExternalOIDCWithUpstreamParity
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IngressControllerDynamicConfigurationManager
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IngressControllerMultipleHAProxyVersions
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IrreconcilableMachineConfig
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| SELinuxMountGAReadiness
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VolumeGroupSnapshot
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| CRIOCredentialProviderConfig
(0 tests)| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled |
| NoRegistryClusterInstall
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| OLMLifecycleAndCompatibility
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| BGPBasedVIPManagement
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
| GCPSovereignCloudInstall
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| GatewayAPIManagementMode
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
### New images
* [haproxy-router-haproxy28](https://github.com/openshift/router) git [4b401a86](https://github.com/openshift/router/commit/4b401a86dccc657a8a5254c2794a312241f40e87) `sha256:2d40fe77aae0973178d8088c53fabf7c6f3de75b9c7a3c5ee4e1bf8d7a82840b`
* [haproxy-router-haproxy32](https://github.com/openshift/router) git [4b401a86](https://github.com/openshift/router/commit/4b401a86dccc657a8a5254c2794a312241f40e87) `sha256:3d7b0fd56f23776bf6b836f894f628e6e5ed717fa35870e6945ac3b74ee69d61`
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [8264c02d](https://github.com/openshift/apiserver-network-proxy/commit/8264c02deda9abb6cd9a6a5c23305428431473c2) `sha256:2893ebcffc81d0ff9f56747e84c9273ae4edc553c5a7206542e40f15812c955a`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:7223f34c717aedc002ac1bdd5579d8a28b437211048478aa9ada1988adc00476`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:4327e93eea4af2369b84a93990f5e2c17b32dff5b389987e07514be6498a6331`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:fa6da7efef7c782e708b9265a237a7bd4cf979d5dc07d74623b590603fd8ba56`
* [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [2b4705c5](https://github.com/openshift/azure-workload-identity/commit/2b4705c5d999339ce17d47a9b2a637d238891dae) `sha256:723363faeff812e7f82dea09cd7b9d4084f47eaa1e3b925604a84cfd7908ac63`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:01d690539ebb09220106c05ae5ce25eedc595a2ac3a3d55d18a90b07f49f9c40`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [7b1593a4](https://github.com/openshift/cluster-bootstrap/commit/7b1593a47898b6a97dc457efaca464624e9f2afa) `sha256:6245992b51fd5259f1e1d6d9f740469bb2dd1171081db26eeb73b5ec6b5e56d2`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:8b8c6402d976b4c49abcb771f3e6b098db897c0b583a26c9828debe42d32a3f6`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [34f95b07](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/34f95b07f4afbc47558e54e4fa2710fd692e615e) `sha256:840dce7a6fa6a7b9711a653105e33283e8f46859f5ef730961aa0e00ff8fcda0`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:3cd4d89d21f59867fc959f37d9110818e6947b86d5f4605a18193c7825f891ac`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:c1ffb648e05c9110caf210b6d1a430e92d25cb158bd0eb49acf44b98c5c38473`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:e2c5596f09a37306d0e3b399c75c8d4312c7626b089d84428dd237edff1b4c96`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:60bd2fbbd206890de03d950c62de27b1623c9cdd51840e5f771f2e07054b3246`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [239703c6](https://github.com/openshift/csi-external-snapshot-metadata/commit/239703c637e005cf785892d214d219add70e3533) `sha256:8419150b270f6c2231ae2ad4fbcc7b84569a389d11d4b0fa1346960b74619891`
* [docker-builder](https://github.com/openshift/builder) git [2cda03a9](https://github.com/openshift/builder/commit/2cda03a93696d4620703848471b3b873b0b2fa1e) `sha256:0561fa5e917568498b5509a2a45eb01b8870dfc291bb4767adbbfe915249964f`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:cb468ed8ee6f4ca20c76f2ef6a9fb4761552c7e1147329905cd588d81b48ae88`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:269d774e041ed5197d920df1ef3e8a3543ca2a78bbab624e1336a623b687f296`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [43c114bc](https://github.com/openshift/kube-rbac-proxy/commit/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d) `sha256:4d6e1112443baa32e3f3662aead489690194269590f85395651ef65744efbfed`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:6853afa91d0ae826aa1234928cac304cb6bb4c48b25ddde76e08cc6d699d2c59`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:fd3603073a6c71241399815768bb0323c56a4bf3d49929b6e8316d5343a342f3`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:90ef5ae6d27423afb0d9a50174814e8664f46d36c6bda2a659749070bac36f27`
* [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [19d390fd](https://github.com/openshift/bond-cni/commit/19d390fd4d353619fdfb5e0070962d2ddf54b5bb) `sha256:41d50f6528f575f7011d9f1edeb600e1d26e86f7254499caa59d7f38da4ae183`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:280ef74a3001edd834f192ba3c1ee21452e090fcee4e5c2a5cd5917498a213db`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [dc584c6b](https://github.com/openshift/cloud-provider-nutanix/commit/dc584c6b2e895a6217f9e2dbed765209af1898a1) `sha256:56a927aaaf91e0da0c48451fd1d4f25cbb5d0dd8e8488578944396573ac3237b`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [5631cf49](https://github.com/openshift/openshift-controller-manager/commit/5631cf493b006cbc72a8600a7435813272d71940) `sha256:5db3ef00c080b3534db7cb99160304ae1228e383d9c4d73ce289f834b03e1655`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:382984c59d8b75981792609c43c322353fe3d90cd37e6798a0fcd87d44f5582e`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:d7975e99bba145d83b42f085c88e103d80e0ff216e8da98fe869d5387db07b71`
* [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver) git [e7c2c09b](https://github.com/openshift/ibm-powervs-block-csi-driver/commit/e7c2c09bd0507f8bd5a6dc3921024a379f4a8af0) `sha256:7b22a57c4765f6a99bc0225ef833f0244e7f3e9d47697ff401d48c4916331322`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [e88cf81d](https://github.com/openshift/machine-api-provider-powervs/commit/e88cf81dd9ad174f395b86f9cdc40fa30cb06bf4) `sha256:2cb2ceee627ed996546a619c8d17bddc8c325e99b150df705483fbd983e1e2e6`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:b2a99c754c085d61602f804dbd641c14f4a083e91eaaf90b435959eabc5a0560`
* [telemeter](https://github.com/openshift/telemeter) git [22ba1701](https://github.com/openshift/telemeter/commit/22ba1701333f3fd26490cc15b89ddf21df3f67f6) `sha256:69b4f79368824191a72fc388fa5a4f30c2439c1e3df931150b4980651b7861fb`
* [vsphere-csi-driver](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:96722803197158f70b310b8c5b754e62cbfc25632f062edc197910fac7ec861a`
* [vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:8089f3ab386b27144195a5c0c4c1665fec0cbc3f1965361eaa658e559f386c13`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/c17225add04bf20d20ed255af0e7a9eaa7498efb)
* [ACM-40452](https://issues.redhat.com/browse/ACM-40452): CVE-2026-33815 Bump github.com/jackc/pgx/v5 to v5.9.0 [#10783](https://github.com/openshift/assisted-service/pull/10783)
* [ACM-40510](https://issues.redhat.com/browse/ACM-40510): Fix infrastructure-operator NetworkPolicy egress to kubernetes API [#10792](https://github.com/openshift/assisted-service/pull/10792)
* NO-ISSUE: Update oc-mirror locations to CGW following openshift release decoupling [#10601](https://github.com/openshift/assisted-service/pull/10601)
* [ACM-40436](https://issues.redhat.com/browse/ACM-40436): Bump Go toolchain to go1.26.5 to fix stdlib CVEs [#10770](https://github.com/openshift/assisted-service/pull/10770)
* [OCPBUGS-93750](https://issues.redhat.com/browse/OCPBUGS-93750): Bump github.com/moby/moby to v28.5.2 [#10680](https://github.com/openshift/assisted-service/pull/10680)
* [MGMT-24827](https://issues.redhat.com/browse/MGMT-24827): Resource-scoped auth for urlAuth endpoints [#10667](https://github.com/openshift/assisted-service/pull/10667)
* [MGMT-24831](https://issues.redhat.com/browse/MGMT-24831): Add ntpSources field to InfraEnv and AgentClusterInstall CRDs [#10756](https://github.com/openshift/assisted-service/pull/10756)
* [ACM-30180](https://issues.redhat.com/browse/ACM-30180): Honor cluster TLS security profile in Infrastructure Operator [#10734](https://github.com/openshift/assisted-service/pull/10734)
* NO-ISSUE: [master] Bump OCP versions: 4.22 [#10735](https://github.com/openshift/assisted-service/pull/10735)
* [MGMT-24939](https://issues.redhat.com/browse/MGMT-24939): (assisted-service) Upgrade operator-sdk from v1.10.1 to v1.42.3 (kubebuilder v3โv4 migration) [#10716](https://github.com/openshift/assisted-service/pull/10716)
* NO-ISSUE: [master] Bump OCP versions: 4.16, 4.14, 5.0 [#10733](https://github.com/openshift/assisted-service/pull/10733)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Fall back to CoreOS image from worker ignition for day-2 persistent-boot [#10717](https://github.com/openshift/assisted-service/pull/10717)
* [MULTIARCH-6274](https://issues.redhat.com/browse/MULTIARCH-6274): agent: Enable platform external s390x [#10424](https://github.com/openshift/assisted-service/pull/10424)
* [MGMT-24352](https://issues.redhat.com/browse/MGMT-24352): Reset finalizing timeout on transition from installing-pending-user-action [#10293](https://github.com/openshift/assisted-service/pull/10293)
* [OCPBUGS-97919](https://issues.redhat.com/browse/OCPBUGS-97919): fix: use typed credentials key to support MAC-based fencing in ABI flow [#10477](https://github.com/openshift/assisted-service/pull/10477)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#10711](https://github.com/openshift/assisted-service/pull/10711)
* [OCPBUGS-91733](https://issues.redhat.com/browse/OCPBUGS-91733): manifest_generator add a label to LUKS root [#10676](https://github.com/openshift/assisted-service/pull/10676)
* NO-ISSUE: [master] Bump OCP versions: 4.18, 4.19 [#10724](https://github.com/openshift/assisted-service/pull/10724)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [SECURITY] [#10718](https://github.com/openshift/assisted-service/pull/10718)
* NO-ISSUE: [master] Bump OCP versions: 4.20, 4.21, 4.22 [#10715](https://github.com/openshift/assisted-service/pull/10715)
* NO-ISSUE: [master] Bump OCP versions: 4.13, 4.18, 4.19 [#10710](https://github.com/openshift/assisted-service/pull/10710)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (client module) [#10617](https://github.com/openshift/assisted-service/pull/10617)
* [MGMT-23744](https://issues.redhat.com/browse/MGMT-23744): CVE-2026-33997 Bump docker/docker to v28.5.2 [#10685](https://github.com/openshift/assisted-service/pull/10685)
* NO-ISSUE: [master] Bump OCP versions: 4.16, 4.14, 4.22, 4.21, 4.19, 4.20, 4.18 [#10692](https://github.com/openshift/assisted-service/pull/10692)
* [MGMT-24667](https://issues.redhat.com/browse/MGMT-24667): Fix disconnected ZTP spoke installs for OCP 5.0 OSImageStream images [#10527](https://github.com/openshift/assisted-service/pull/10527)
* [MGMT-24699](https://issues.redhat.com/browse/MGMT-24699): Assisted Service IPv6 CIDR comparison may fail with non-normalized CIDRs [#10569](https://github.com/openshift/assisted-service/pull/10569)
* [MGMT-24327](https://issues.redhat.com/browse/MGMT-24327): upgrade assisted-service postgresql from 15 to 16 [#10519](https://github.com/openshift/assisted-service/pull/10519)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (api module) [#10618](https://github.com/openshift/assisted-service/pull/10618)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (models module) [#10616](https://github.com/openshift/assisted-service/pull/10616)
* NO-ISSUE: [master] Bump OCP versions: 4.18, 5.0, 4.20, 4.16, 4.22, 4.19, 4.21, 4.14, 4.17 [#10622](https://github.com/openshift/assisted-service/pull/10622)
* [MGMT-24786](https://issues.redhat.com/browse/MGMT-24786): Add resource-scoped authorization for local auth tokens [#10603](https://github.com/openshift/assisted-service/pull/10603)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-service/compare/ad9783f44c2b9e147e8897b8cde00bfe06410d74...c17225add04bf20d20ed255af0e7a9eaa7498efb)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/880389d450131a12a888202877b28dbae61ac0da)
* [OCPBUGS-101647](https://issues.redhat.com/browse/OCPBUGS-101647): Bump golang.org/x/net to v0.56.0 [#2251](https://github.com/openshift/assisted-installer/pull/2251)
* [MGMT-24598](https://issues.redhat.com/browse/MGMT-24598): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#2219](https://github.com/openshift/assisted-installer/pull/2219)
* [OCPBUGS-96799](https://issues.redhat.com/browse/OCPBUGS-96799): Bump golang.org/x/net from v0.48.0 to v0.55.0 [#2244](https://github.com/openshift/assisted-installer/pull/2244)
* [OCPBUGS-96696](https://issues.redhat.com/browse/OCPBUGS-96696): Wait for all nodes to join before exiting for ABI [#2230](https://github.com/openshift/assisted-installer/pull/2230)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#2224](https://github.com/openshift/assisted-installer/pull/2224)
* [MGMT-24702](https://issues.redhat.com/browse/MGMT-24702): CVE-2026-53488 Bump github.com/containerd/containerd to v1.7.33 [#2204](https://github.com/openshift/assisted-installer/pull/2204)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/019fed042d5aff7e5d390f00d4e4e8a712e4da40...880389d450131a12a888202877b28dbae61ac0da)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/aeec165131a4c528174a58a011d1c3c31cfd7cc1)
* [MGMT-24597](https://issues.redhat.com/browse/MGMT-24597): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#1560](https://github.com/openshift/assisted-installer-agent/pull/1560)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#1578](https://github.com/openshift/assisted-installer-agent/pull/1578)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Preserve encapsulated MachineConfig in filtered ignition [#1568](https://github.com/openshift/assisted-installer-agent/pull/1568)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#1555](https://github.com/openshift/assisted-installer-agent/pull/1555)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/f84fd71b5732db9c0caf2d11672d579b2c3ea588...aeec165131a4c528174a58a011d1c3c31cfd7cc1)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/1487057fac3ed41577778fe4fa470646e9962cf7)
* [OCPBUGS-104439](https://issues.redhat.com/browse/OCPBUGS-104439): pin postcss resolution to >=8.5.23 (CVE-2026-69153) (#3957) [#3957](https://github.com/openshift-assisted/assisted-installer-ui/pull/3957)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): Remove CustomNoUpgrade featureSet and NoRegistryClusterInstall feature gate (#3954) [#3954](https://github.com/openshift-assisted/assisted-installer-ui/pull/3954)
* Bump js-yaml from 3.14.1 to 4.3.1 (#3951) [#3951](https://github.com/openshift-assisted/assisted-installer-ui/pull/3951)
* Bump js-yaml from 4.3.0 to 4.3.1 (#3947) [#3947](https://github.com/openshift-assisted/assisted-installer-ui/pull/3947)
* chore(deps): update dependency ws to ^8.21.2 (#3950) [#3950](https://github.com/openshift-assisted/assisted-installer-ui/pull/3950)
* chore(deps): update dependency dompurify to ^3.4.13 (#3949) [#3949](https://github.com/openshift-assisted/assisted-installer-ui/pull/3949)
* chore(deps): update konflux references (#3946) [#3946](https://github.com/openshift-assisted/assisted-installer-ui/pull/3946)
* Add 'Storage class' option to Hypeshift details form (#3944) [#3944](https://github.com/openshift-assisted/assisted-installer-ui/pull/3944)
* [MGMT-24973](https://issues.redhat.com/browse/MGMT-24973): Fix missing padding on InfraEnv error alerts in the Add hosts modal (#3943) [#3943](https://github.com/openshift-assisted/assisted-installer-ui/pull/3943)
* Bump ip-address from 10.2.0 to 10.3.1 (#3938) [#3938](https://github.com/openshift-assisted/assisted-installer-ui/pull/3938)
* Add OptionalConfigurationStep (#3927) [#3927](https://github.com/openshift-assisted/assisted-installer-ui/pull/3927)
* chore(deps): update konflux references (#3933) [#3933](https://github.com/openshift-assisted/assisted-installer-ui/pull/3933)
* Bump undici from 7.28.0 to 7.29.0 (#3940) [#3940](https://github.com/openshift-assisted/assisted-installer-ui/pull/3940)
* Bump fast-uri from 3.1.4 to 3.1.5 (#3939) [#3939](https://github.com/openshift-assisted/assisted-installer-ui/pull/3939)
* chore(deps): update dependency minimatch to ^10.2.6 (#3936) [#3936](https://github.com/openshift-assisted/assisted-installer-ui/pull/3936)
* NO-ISSUE: Silence TypeScript deprecation warning (#3937) [#3937](https://github.com/openshift-assisted/assisted-installer-ui/pull/3937)
* chore(deps): update dependency brace-expansion to ^5.0.9 (#3935) [#3935](https://github.com/openshift-assisted/assisted-installer-ui/pull/3935)
* Keep NMState resources when deleting BMC hosts (#3931) [#3931](https://github.com/openshift-assisted/assisted-installer-ui/pull/3931)
* Block installation when custom-manifests-requirements-satisfied validation fails (#3923) [#3923](https://github.com/openshift-assisted/assisted-installer-ui/pull/3923)
* Upgrade react-router to ^7.18.1 (#3925) [#3925](https://github.com/openshift-assisted/assisted-installer-ui/pull/3925)
* [MGMT-24641](https://issues.redhat.com/browse/MGMT-24641): Attempt to choose 5 masters for standalone cluster blocked (#3912) [#3912](https://github.com/openshift-assisted/assisted-installer-ui/pull/3912)
* Bump tar from 7.5.20 to 7.5.22 (#3921) [#3921](https://github.com/openshift-assisted/assisted-installer-ui/pull/3921)
* Bump postcss from 8.5.15 to 8.5.23 (#3920) [#3920](https://github.com/openshift-assisted/assisted-installer-ui/pull/3920)
* Bump uuid from 8.3.2 to 14.0.1 (#3919) [#3919](https://github.com/openshift-assisted/assisted-installer-ui/pull/3919)
* chore(deps): update dependency brace-expansion to ^5.0.8 (#3916) [#3916](https://github.com/openshift-assisted/assisted-installer-ui/pull/3916)
* chore(deps): update dependency dompurify to ^3.4.12 (#3917) [#3917](https://github.com/openshift-assisted/assisted-installer-ui/pull/3917)
* chore(deps): update konflux references (#3913) [#3913](https://github.com/openshift-assisted/assisted-installer-ui/pull/3913)
* Bump shell-quote from 1.8.4 to 1.10.0 (#3909) [#3909](https://github.com/openshift-assisted/assisted-installer-ui/pull/3909)
* Bump body-parser from 1.20.4 to 1.20.6 (#3911) [#3911](https://github.com/openshift-assisted/assisted-installer-ui/pull/3911)
* Bump fast-uri from 3.1.2 to 3.1.4 (#3910) [#3910](https://github.com/openshift-assisted/assisted-installer-ui/pull/3910)
* [OCPBUGS-99039](https://issues.redhat.com/browse/OCPBUGS-99039): Bump dompurify to 3.4.7+ in 5.0 (#3894) [#3894](https://github.com/openshift-assisted/assisted-installer-ui/pull/3894)
* Update build_tools (#3901) [#3901](https://github.com/openshift-assisted/assisted-installer-ui/pull/3901)
* Fix operator Learn more documentation links and remove duplicates (#3899) [#3899](https://github.com/openshift-assisted/assisted-installer-ui/pull/3899)
* chore(deps): update dependency sanitize-html to ^2.17.6 (#3897) [#3897](https://github.com/openshift-assisted/assisted-installer-ui/pull/3897)
* Bump websocket-driver from 0.7.4 to 0.7.5 (#3891) [#3891](https://github.com/openshift-assisted/assisted-installer-ui/pull/3891)
* chore(deps): update dependency tar to ^7.5.20 (#3898) [#3898](https://github.com/openshift-assisted/assisted-installer-ui/pull/3898)
* chore(deps): update konflux references (#3896) [#3896](https://github.com/openshift-assisted/assisted-installer-ui/pull/3896)
* Upgrade node version in Containerfile (#3872) [#3872](https://github.com/openshift-assisted/assisted-installer-ui/pull/3872)
* Apply patches (#3819) [#3819](https://github.com/openshift-assisted/assisted-installer-ui/pull/3819)
* Upgrade path-to-regexp to ^8.4.2 (#3862) [#3862](https://github.com/openshift-assisted/assisted-installer-ui/pull/3862)
* Upgrade sanitize-html to ^2.17.4 (#3861) [#3861](https://github.com/openshift-assisted/assisted-installer-ui/pull/3861)
* Dedupe yarn.lock (#3863) [#3863](https://github.com/openshift-assisted/assisted-installer-ui/pull/3863)
* Upgrade terser-webpack-plugin to ^5.6.1 (#3818) [#3818](https://github.com/openshift-assisted/assisted-installer-ui/pull/3818)
* chore(deps): update typescript type definitions (non-major) (#3867) [#3867](https://github.com/openshift-assisted/assisted-installer-ui/pull/3867)
* chore(deps): update dependency axios to ^1.18.1 (#3868) [#3868](https://github.com/openshift-assisted/assisted-installer-ui/pull/3868)
* chore(deps): update konflux references (#3866) [#3866](https://github.com/openshift-assisted/assisted-installer-ui/pull/3866)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/3aadc22a8cc9849b0907ba6082b759b8c51c90cb...1487057fac3ed41577778fe4fa470646e9962cf7)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/33aa46920190a1c587599dfda77d9c1e3899e255)
* [OCPBUGS-105450](https://issues.redhat.com/browse/OCPBUGS-105450): Update Konflux references [#334](https://github.com/openshift/agent-installer-utils/pull/334)
* [OCPBUGS-101759](https://issues.redhat.com/browse/OCPBUGS-101759): Update Konflux references [#331](https://github.com/openshift/agent-installer-utils/pull/331)
* [OCPBUGS-99905](https://issues.redhat.com/browse/OCPBUGS-99905): Update Konflux references [#303](https://github.com/openshift/agent-installer-utils/pull/303)
* [OCPBUGS-99745](https://issues.redhat.com/browse/OCPBUGS-99745): Use Operator catalog in 4.22 for OVE [#323](https://github.com/openshift/agent-installer-utils/pull/323)
* [OCPBUGS-87367](https://issues.redhat.com/browse/OCPBUGS-87367): Updating ose-agent-installer-utils-container image to be consistent with ART for 5.0 [#308](https://github.com/openshift/agent-installer-utils/pull/308)
* [OCPBUGS-99425](https://issues.redhat.com/browse/OCPBUGS-99425): Use agent-preinstall-image-builder from quay-proxy [#319](https://github.com/openshift/agent-installer-utils/pull/319)
* [OCPBUGS-98692](https://issues.redhat.com/browse/OCPBUGS-98692): Update cluster-logging and loki operator versions [#315](https://github.com/openshift/agent-installer-utils/pull/315)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/001a8f25faafa0290483617c2f73fdf15dbc25fc...33aa46920190a1c587599dfda77d9c1e3899e255)
### [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws/tree/278e8c07a72a50e7d3f28fc743c38c64f008f5aa)
* [OCPCLOUD-3643](https://issues.redhat.com/browse/OCPCLOUD-3643): Merge https://github.com/kubernetes/cloud-provider-aws:master (63ec440) into main [#160](https://github.com/openshift/cloud-provider-aws/pull/160)
* [Full changelog](https://github.com/openshift/cloud-provider-aws/compare/5060934bc9ff325acf4bd0728bf37166255a501f...278e8c07a72a50e7d3f28fc743c38c64f008f5aa)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/e345a83efda50037cd59ae0741a62cf7169f5def)
* โจ OCPCLOUD-3513: feat: add gh-summary target to download manifests from GitHub [#617](https://github.com/openshift/cluster-api-provider-aws/pull/617)
* โจ OCPCLOUD-3513: add a tool to generate manifests-summary [#616](https://github.com/openshift/cluster-api-provider-aws/pull/616)
* ๐OCPBUGS-104496: UPSTREAM: <carry>: Add projected bound SA token volume for OpenShift [#624](https://github.com/openshift/cluster-api-provider-aws/pull/624)
* โจ OCPCLOUD-3538,OCPCLOUD-3556: Exclude unsupported CAPI CRDs and scope ClusterRole [#618](https://github.com/openshift/cluster-api-provider-aws/pull/618)
* ๐ฑ OCPCLOUD-3599: Merge https://github.com/kubernetes-sigs/cluster-api-provider-aws:v2.13.0 (a84670f) into main [#623](https://github.com/openshift/cluster-api-provider-aws/pull/623)
* :seedling: OCPBUGS-95028: bump golang.org/x/net to v0.55.0 for CVE-2026-25681 [#622](https://github.com/openshift/cluster-api-provider-aws/pull/622)
* :rocket: UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-aws:v2.12.1 (13af066) into main [#621](https://github.com/openshift/cluster-api-provider-aws/pull/621)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/c2dd5cd7921fa56b05f7c95b333ee3f59f850bc5...e345a83efda50037cd59ae0741a62cf7169f5def)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/756f6b8bb00400e3d72437876a820a950c393eb3)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Remove legacy gcp-pd-csi-driver-operator [#592](https://github.com/openshift/csi-operator/pull/592)
* [STOR-3060](https://issues.redhat.com/browse/STOR-3060), [STOR-3061](https://issues.redhat.com/browse/STOR-3061): implement TLS adherence for AWS EFS and SMB CSI driver operator [#587](https://github.com/openshift/csi-operator/pull/587)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Copy the test manifests from the `legacy` dir to a top-level `test` dir [#589](https://github.com/openshift/csi-operator/pull/589)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Auto generate assets for gcp pd csi driver [#585](https://github.com/openshift/csi-operator/pull/585)
* [OCPBUGS-99199](https://issues.redhat.com/browse/OCPBUGS-99199): Add networking.k8s.io group policy [#579](https://github.com/openshift/csi-operator/pull/579)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#582](https://github.com/openshift/csi-operator/pull/582)
* [OCPBUGS-99200](https://issues.redhat.com/browse/OCPBUGS-99200): Add networking.k8s.io group policy [#581](https://github.com/openshift/csi-operator/pull/581)
* [OCPBUGS-99490](https://issues.redhat.com/browse/OCPBUGS-99490): Apply some static assets earlier, before starting controllers [#584](https://github.com/openshift/csi-operator/pull/584)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Minimal implementation of GCP PD CSI driver operator [#576](https://github.com/openshift/csi-operator/pull/576)
* [Full changelog](https://github.com/openshift/csi-operator/compare/1f648349427a0f61e3022f8ec20f270394dc80c5...756f6b8bb00400e3d72437876a820a950c393eb3)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/dc822233cc526b6cc55f20009a4c1b034f245133)
* [OCPBUGS-100043](https://issues.redhat.com/browse/OCPBUGS-100043): Updating aws-karpenter-provider-aws-container image to be consistent with ART for 5.0 [#34](https://github.com/openshift/aws-karpenter-provider-aws/pull/34)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): Release chores 5.0 for Karpenter [#33](https://github.com/openshift/aws-karpenter-provider-aws/pull/33)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/d8187d40117d334c5bb6e4b4f9613b617dc8e45c...dc822233cc526b6cc55f20009a4c1b034f245133)
### [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider/tree/9b18930d2db9521a08faa7165488bdcf6482b9cf)
* [CNTRLPLANE-4011](https://issues.redhat.com/browse/CNTRLPLANE-4011): Rebase aws-encryption-provider repo to upstream/master (8c16f8c) for OCP 5.0 [#52](https://github.com/openshift/aws-encryption-provider/pull/52)
* [Full changelog](https://github.com/openshift/aws-encryption-provider/compare/6ca6eea2f3a9d0b090ff63ba5b8e342d5686c9a8...9b18930d2db9521a08faa7165488bdcf6482b9cf)
### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/9f2e9b3c46b391c7219257a426ad80ca8a296af0)
* [OCPCLOUD-3615](https://issues.redhat.com/browse/OCPCLOUD-3615): Bump k8s to 1.36 and Go to 1.26 [#197](https://github.com/openshift/machine-api-provider-aws/pull/197)
* [OCPBUGS-47508](https://issues.redhat.com/browse/OCPBUGS-47508): Add max-concurrent-reconciles flag to machine actuator [#195](https://github.com/openshift/machine-api-provider-aws/pull/195)
* NO-JIRA: Bump golang.org/x/crypto to fix CVE [#194](https://github.com/openshift/machine-api-provider-aws/pull/194)
* [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/10718580c265686b6af85caab68eed263eee2a41...9f2e9b3c46b391c7219257a426ad80ca8a296af0)
### [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook/tree/0d33a4596e2a22d188fe74c4a6497c37c2528c1f)
* [OCPCLOUD-3583](https://issues.redhat.com/browse/OCPCLOUD-3583): Update aws-pod-identity-webhook to k8s 1.36 [#220](https://github.com/openshift/aws-pod-identity-webhook/pull/220)
* [Full changelog](https://github.com/openshift/aws-pod-identity-webhook/compare/631a2f5496d1cb29eaaedac38c199a8c3ba9b0af...0d33a4596e2a22d188fe74c4a6497c37c2528c1f)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/b99e4ce4ff5c2665b273384b0673824833c40ce5)
* [OCPBUGS-100185](https://issues.redhat.com/browse/OCPBUGS-100185): fix: use PATCH when refreshing failed VMs [#201](https://github.com/openshift/cloud-provider-azure/pull/201)
* [OCPCLOUD-3591](https://issues.redhat.com/browse/OCPCLOUD-3591): Merge https://github.com/kubernetes-sigs/cloud-provider-azure:master (4128235) into main [#164](https://github.com/openshift/cloud-provider-azure/pull/164)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/d04449b95a54a9f41669d701ed63153575cced1e...b99e4ce4ff5c2665b273384b0673824833c40ce5)
### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/63731729974bff3be90ae2206c53d760572499d1)
* ๐ OCPCLOUD-3600: Merge https://github.com/kubernetes-sigs/cluster-api-provider-azure:v1.26.0 (19ff821) into main [#388](https://github.com/openshift/cluster-api-provider-azure/pull/388)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#393](https://github.com/openshift/cluster-api-provider-azure/pull/393)
* [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/52af3f1a3ecffec69c621e80bc80adf67ecec7c0...63731729974bff3be90ae2206c53d760572499d1)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/c5e303bb0c6a55332637d7a583cfceec1a3a900b)
* [OCPBUGS-101779](https://issues.redhat.com/browse/OCPBUGS-101779): UPSTREAM: 3756: fix: optionally skip reading the config from the API server [#159](https://github.com/openshift/azure-disk-csi-driver/pull/159)
* [OCPBUGS-96820](https://issues.redhat.com/browse/OCPBUGS-96820): Bump golang.org/x/net from v0.52.0 to v0.55.0 [#156](https://github.com/openshift/azure-disk-csi-driver/pull/156)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/e87f776402d402a3e291e24fa737fe4e5e9617aa...c5e303bb0c6a55332637d7a583cfceec1a3a900b)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/9689f03011ce700b3bffc32791af839e80d0e0ab)
* [STOR-2928](https://issues.redhat.com/browse/STOR-2928): Rebase to v1.35.5 for OCP 5.0 [#143](https://github.com/openshift/azure-file-csi-driver/pull/143)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/f7724fbf3ad694f957bd99fafa2fa7b658462624...9689f03011ce700b3bffc32791af839e80d0e0ab)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/11f4f7cc51f482bfd778c3574ad6b5087165d59a)
* [OCPSTRAT-3549](https://issues.redhat.com/browse/OCPSTRAT-3549): Correct Managed HSM endpoints [#51](https://github.com/openshift/azure-kubernetes-kms/pull/51)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/ca3d747de321b88a2c606e546851d1841d2fab9f...11f4f7cc51f482bfd778c3574ad6b5087165d59a)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/4ff6c6b8730c1253918f1f5261b9c12cab2e5903)
* [OCPCLOUD-3616](https://issues.redhat.com/browse/OCPCLOUD-3616): Bump k8s to 1.36 and Go to 1.26 [#206](https://github.com/openshift/machine-api-provider-azure/pull/206)
* [OCPBUGS-92024](https://issues.redhat.com/browse/OCPBUGS-92024), [OCPBUGS-98075](https://issues.redhat.com/browse/OCPBUGS-98075): bump golang.org/x/crypto to v0.54.0 to fix CVEs [#203](https://github.com/openshift/machine-api-provider-azure/pull/203)
* [OCPBUGS-96854](https://issues.redhat.com/browse/OCPBUGS-96854): bump golang.org/x/net to v0.55.0 [#204](https://github.com/openshift/machine-api-provider-azure/pull/204)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/bb01d0dfee4abfe7274ff96cba280ad81ad99936...4ff6c6b8730c1253918f1f5261b9c12cab2e5903)
### [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3/tree/ad4f1c2bd7b527437496b71b5b93ee1439243d65)
* [OCPBUGS-98546](https://issues.redhat.com/browse/OCPBUGS-98546): Remove dangling symlink [#87](https://github.com/openshift/cluster-api-provider-metal3/pull/87)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#85](https://github.com/openshift/cluster-api-provider-metal3/pull/85)
* [OCPBUGS-98329](https://issues.redhat.com/browse/OCPBUGS-98329): Grant capi-installer permission on ConfigMap [#86](https://github.com/openshift/cluster-api-provider-metal3/pull/86)
* [Full changelog](https://github.com/openshift/cluster-api-provider-metal3/compare/29a96694bfc3b59d1fa95acf2ad87077cc1d3108...ad4f1c2bd7b527437496b71b5b93ee1439243d65)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/7bd5ebb0831e2eea150a7cf145289e72b42edc1a)
* [OCPBUGS-88511](https://issues.redhat.com/browse/OCPBUGS-88511): Disable apps DNS validation for add-nodes [#10737](https://github.com/openshift/installer/pull/10737)
* NO-JIRA: openstack: pin argcomplete for yq on Python 3.9 [#10757](https://github.com/openshift/installer/pull/10757)
* NO-ISSUE: Render OSImageStream in OKD too [#10730](https://github.com/openshift/installer/pull/10730)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate [#10760](https://github.com/openshift/installer/pull/10760)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): vsphere: remove VSphereMultiDisk feature gate references [#10753](https://github.com/openshift/installer/pull/10753)
* no-jira: Update GCD ability to identify project [#10745](https://github.com/openshift/installer/pull/10745)
* no-jira: vendor: update o/api to the latest after several Feature promotions to default [#10746](https://github.com/openshift/installer/pull/10746)
* [OCPBUGS-101695](https://issues.redhat.com/browse/OCPBUGS-101695): bump golang.org/x/net to v0.56.0 [#10749](https://github.com/openshift/installer/pull/10749)
* [OCPBUGS-85296](https://issues.redhat.com/browse/OCPBUGS-85296): export Azure Metadata.Region for state file serialization [#10736](https://github.com/openshift/installer/pull/10736)
* [CORS-4406](https://issues.redhat.com/browse/CORS-4406): CORS-4407: CORS-4408: CORS-4410: CORS-4411: CORS-4413: Installer use customer managed kms keys to encrypt S3 for Ignition and Internal Registry [#10553](https://github.com/openshift/installer/pull/10553)
* [OCPBUGS-100189](https://issues.redhat.com/browse/OCPBUGS-100189): Patch GCP Load Balancer Health Checks [#10731](https://github.com/openshift/installer/pull/10731)
* [OCPBUGS-98700](https://issues.redhat.com/browse/OCPBUGS-98700): Azure: delete bootstrap ignition storage during bootstrap destroy [#10701](https://github.com/openshift/installer/pull/10701)
* [OCPBUGS-78995](https://issues.redhat.com/browse/OCPBUGS-78995): Azure Machines: Accept explicit image ID [#10712](https://github.com/openshift/installer/pull/10712)
* [OCPBUGS-104455](https://issues.redhat.com/browse/OCPBUGS-104455): Add a 10sec restart interval for ICC service, so that there is enough time for CRDs to become available [#10739](https://github.com/openshift/installer/pull/10739)
* no-jira: Update hack scripts to set min go version to 1.26 [#10738](https://github.com/openshift/installer/pull/10738)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Configure cloud provider to use mounted creds [#10733](https://github.com/openshift/installer/pull/10733)
* [OCPBUGS-98102](https://issues.redhat.com/browse/OCPBUGS-98102): Add validations Azure Dualstack [#10677](https://github.com/openshift/installer/pull/10677)
* [CORS-4537](https://issues.redhat.com/browse/CORS-4537): GCP: gracefully handle 503 in disk type check [#10732](https://github.com/openshift/installer/pull/10732)
* [CORS-3898](https://issues.redhat.com/browse/CORS-3898): azure: Fix the dualstack errors [#10656](https://github.com/openshift/installer/pull/10656)
* [OCPEDGE-2788](https://issues.redhat.com/browse/OCPEDGE-2788): agent: split fencing credentials placement by identification key [#10684](https://github.com/openshift/installer/pull/10684)
* [OCPBUGS-99164](https://issues.redhat.com/browse/OCPBUGS-99164): bootstrap: replace envsubst with sed in konnectivity.sh [#10728](https://github.com/openshift/installer/pull/10728)
* [CORS-4542](https://issues.redhat.com/browse/CORS-4542): restrict ClusterAPI machine management to only supported platforms [#10717](https://github.com/openshift/installer/pull/10717)
* [CORS-4425](https://issues.redhat.com/browse/CORS-4425): gcp: add OS image validation for sovereign clouds [#10709](https://github.com/openshift/installer/pull/10709)
* [CNTRLPLANE-2012](https://issues.redhat.com/browse/CNTRLPLANE-2012): Wire signer certs to read PKI config via SignerKeyParams [#10595](https://github.com/openshift/installer/pull/10595)
* [OCPBUGS-63133](https://issues.redhat.com/browse/OCPBUGS-63133): PowerVS: Error out if VPC does not exist [#10137](https://github.com/openshift/installer/pull/10137)
* [OCPBUGS-98696](https://issues.redhat.com/browse/OCPBUGS-98696): baremetal: fix provisioning ISO kernel arguments [#10702](https://github.com/openshift/installer/pull/10702)
* no-jira: bump k8s packages to v0.36 [#10713](https://github.com/openshift/installer/pull/10713)
* [CORS-4428](https://issues.redhat.com/browse/CORS-4428): gcp: reject PSC endpoint overrides for sovereign clouds [#10708](https://github.com/openshift/installer/pull/10708)
* [CORS-4514](https://issues.redhat.com/browse/CORS-4514): Set sovereign cloud defaults for machine types [#10706](https://github.com/openshift/installer/pull/10706)
* [CORS-4537](https://issues.redhat.com/browse/CORS-4537): Add API-backed disk type availability validation [#10687](https://github.com/openshift/installer/pull/10687)
* no-jira: azure: Disable shared access key by default [#10574](https://github.com/openshift/installer/pull/10574)
* [CORS-4507](https://issues.redhat.com/browse/CORS-4507): aws: support edge machine pool management with ClusterAPI [#10625](https://github.com/openshift/installer/pull/10625)
* [CNTRLPLANE-2847](https://issues.redhat.com/browse/CNTRLPLANE-2847): bootstrap: pass rendered manifests and payload version to etcd render [#10679](https://github.com/openshift/installer/pull/10679)
* [CORS-3997](https://issues.redhat.com/browse/CORS-3997): azure: update default instance types from v3 to AMD Dasv5 [#10565](https://github.com/openshift/installer/pull/10565)
* [OCPBUGS-98141](https://issues.redhat.com/browse/OCPBUGS-98141), [OCPBUGS-99018](https://issues.redhat.com/browse/OCPBUGS-99018): bump golang.org/x/crypto to v0.52.0 [#10690](https://github.com/openshift/installer/pull/10690)
* [CORS-4539](https://issues.redhat.com/browse/CORS-4539): Support sovereign cloud service account email format for gcp/gcd [#10691](https://github.com/openshift/installer/pull/10691)
* [CORS-4538](https://issues.redhat.com/browse/CORS-4538): Use metadata project ID for sovereign cloud gather [#10688](https://github.com/openshift/installer/pull/10688)
* NO-ISSUE: Remove workaround for boot image version mismatch [#10665](https://github.com/openshift/installer/pull/10665)
* [OCPBUGS-98586](https://issues.redhat.com/browse/OCPBUGS-98586): Don't wait on oc delete in konnectivity_cleanup [#10682](https://github.com/openshift/installer/pull/10682)
* [OCPBUGS-98529](https://issues.redhat.com/browse/OCPBUGS-98529): cluster-api: disable diagnostics endpoint for local CAPI controllers [#10681](https://github.com/openshift/installer/pull/10681)
* [CORS-4423](https://issues.redhat.com/browse/CORS-4423): GCP: Use WithCredentialsJSON when Possible [#10624](https://github.com/openshift/installer/pull/10624)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/installer/compare/7adbf7cc743214d2a176a4552fd9db4a0371ec5b...7bd5ebb0831e2eea150a7cf145289e72b42edc1a)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/34bbeb376836bf01793d4e70d29065d619ebcaa1)
* NO-ISSUE: Merge upstream 2026-07-30 [#516](https://github.com/openshift/baremetal-operator/pull/516)
* NO-ISSUE: Merge upstream 2026-07-25 [#513](https://github.com/openshift/baremetal-operator/pull/513)
* [METAL-1900](https://issues.redhat.com/browse/METAL-1900): Merge upstream [#510](https://github.com/openshift/baremetal-operator/pull/510)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/5d3be9399c46e8789a6e735672c5fb7abc4b46bd...34bbeb376836bf01793d4e70d29065d619ebcaa1)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/660073616802e3d1258a036f2e57ca18a7baafa0)
* [OCPBUGS-99496](https://issues.redhat.com/browse/OCPBUGS-99496): Detect bootstrap apiserver shutdown via /readyz [#396](https://github.com/openshift/baremetal-runtimecfg/pull/396)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/079091da0e619331ec79b87e466781efe2445411...660073616802e3d1258a036f2e57ca18a7baafa0)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/77a4a5ad7de78a1d24063a384cb0809f50653eea)
* [OCPBUGS-85019](https://issues.redhat.com/browse/OCPBUGS-85019): oc login: Fix polluting KUBECONFIG file [#2357](https://github.com/openshift/oc/pull/2357)
* NO-JIRA: Fix issues collection when CVO handles the risks [#2352](https://github.com/openshift/oc/pull/2352)
* [OCPBUGS-99013](https://issues.redhat.com/browse/OCPBUGS-99013): inspect: Redact OAuthClient secrets [#2354](https://github.com/openshift/oc/pull/2354)
* [OTA-1959](https://issues.redhat.com/browse/OTA-1959): Case 1 - `oc adm upgrade recommend` shows both Cincinnati-sourced and alert-sourced risks in output [#2349](https://github.com/openshift/oc/pull/2349)
* NO-JIRA: Update docs.openshift.com base URL to point to OCP docs [#2353](https://github.com/openshift/oc/pull/2353)
* [OCPBUGS-101781](https://issues.redhat.com/browse/OCPBUGS-101781): Isolate OCP-42982 kubeconfig writes [#2337](https://github.com/openshift/oc/pull/2337)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Handle accept risks with different commands [#2336](https://github.com/openshift/oc/pull/2336)
* [OCPBUGS-100310](https://issues.redhat.com/browse/OCPBUGS-100310): oc login --exec-plugin oc-oidc fails to refresh expired token against Microsoft Entra ID [#2332](https://github.com/openshift/oc/pull/2332)
* Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" [#2322](https://github.com/openshift/oc/pull/2322)
* [OCPBUGS-99757](https://issues.redhat.com/browse/OCPBUGS-99757): Include extra scopes in OIDC token cache key [#2323](https://github.com/openshift/oc/pull/2323)
* [TRT-2817](https://issues.redhat.com/browse/TRT-2817): Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning" [#2320](https://github.com/openshift/oc/pull/2320)
* NO-JIRA: Bump k8s dependencies to 1.36 along with openshift [#2318](https://github.com/openshift/oc/pull/2318)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): fix(alerts): Remove duplicate information in the recommend command [#2279](https://github.com/openshift/oc/pull/2279)
* NO-JIRA: Handle wrapped ENOTSUP error [#2311](https://github.com/openshift/oc/pull/2311)
* NO-JIRA: First try newer iotop-c and fallback to older one [#2317](https://github.com/openshift/oc/pull/2317)
* NO-JIRA: Register the e2e tests for accept in the subfolder [#2300](https://github.com/openshift/oc/pull/2300)
* NO-JIRA: Fix staticcheck warnings in pkg/cli/admin/mustgather [#2306](https://github.com/openshift/oc/pull/2306)
* And 3 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/oc/compare/22c69c0ff5da7e390b42880141e43d555e38ef41...77a4a5ad7de78a1d24063a384cb0809f50653eea)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/b187feee66f4ce0f992059b21a97a2ae88e4cdd9)
* [CORS-4544](https://issues.redhat.com/browse/CORS-4544): WIF Support on GCD [#1073](https://github.com/openshift/cloud-credential-operator/pull/1073)
* [CCO-848](https://issues.redhat.com/browse/CCO-848): Add tls-min-version and tls-cipher-suites CLI flags to CCO [#1063](https://github.com/openshift/cloud-credential-operator/pull/1063)
* [OCPBUGS-83624](https://issues.redhat.com/browse/OCPBUGS-83624): Embed credentials_request.yaml template in test binary [#1072](https://github.com/openshift/cloud-credential-operator/pull/1072)
* [CCO-837](https://issues.redhat.com/browse/CCO-837): Replace deprecated golang/mock with go.uber.org/mock [#1069](https://github.com/openshift/cloud-credential-operator/pull/1069)
* NO-ISSUE: Add patrickdillon to OWNERS [#1071](https://github.com/openshift/cloud-credential-operator/pull/1071)
* [CCO-834](https://issues.redhat.com/browse/CCO-834), [CCO-835](https://issues.redhat.com/browse/CCO-835), [CCO-836](https://issues.redhat.com/browse/CCO-836): Upgrade to Kubernetes 1.36 with CI and e2e tests [#1066](https://github.com/openshift/cloud-credential-operator/pull/1066)
* [CORS-4524](https://issues.redhat.com/browse/CORS-4524): Enable GCP custom universe domain support for CCO [#1068](https://github.com/openshift/cloud-credential-operator/pull/1068)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/672b790022dbea667460b1a0467b6a0bc39c544b...b187feee66f4ce0f992059b21a97a2ae88e4cdd9)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/dada7547e3d89f301be73b27063ac91f2acb9088)
* [CORS-4523](https://issues.redhat.com/browse/CORS-4523): support GCP custom universe domain [#249](https://github.com/openshift/cloud-network-config-controller/pull/249)
* NO-JIRA: Update OWNERS file [#229](https://github.com/openshift/cloud-network-config-controller/pull/229)
* [CORENET-7047](https://issues.redhat.com/browse/CORENET-7047): CNCC K8s rebase to 1.36.2 [#223](https://github.com/openshift/cloud-network-config-controller/pull/223)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/0b49df2bc4b10110463f1aa2a5fc475ebaeef9ab...dada7547e3d89f301be73b27063ac91f2acb9088)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/df5510986bb1d27b8ff10fe02cfc118fabc706d4)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#968](https://github.com/openshift/cluster-authentication-operator/pull/968)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support- #747 [#965](https://github.com/openshift/cluster-authentication-operator/pull/965)
* [CNTRLPLANE-2589](https://issues.redhat.com/browse/CNTRLPLANE-2589): Migrate test/e2e-oidc to OTE + bug fixes(imagestream,scc,Pathological Event Monitor) [#945](https://github.com/openshift/cluster-authentication-operator/pull/945)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Watch openshift-config ConfigMaps in OAuth route health check controller [#964](https://github.com/openshift/cluster-authentication-operator/pull/964)
* NO-JIRA: bump library-go api and client-go [#963](https://github.com/openshift/cluster-authentication-operator/pull/963)
* NO-JIRA: Bump library-go [#962](https://github.com/openshift/cluster-authentication-operator/pull/962)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Include system cert pool in proxy resolver transport [#961](https://github.com/openshift/cluster-authentication-operator/pull/961)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Clear IdP validation hash when all identity providers are removed [#960](https://github.com/openshift/cluster-authentication-operator/pull/960)
* NO-JIRA: Update openshift/* [#959](https://github.com/openshift/cluster-authentication-operator/pull/959)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Add support for component-scoped proxy [#946](https://github.com/openshift/cluster-authentication-operator/pull/946)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client- #741 [#958](https://github.com/openshift/cluster-authentication-operator/pull/958)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#956](https://github.com/openshift/cluster-authentication-operator/pull/956)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): bugfix: make switched controller clear status conditions on delegate controller shutdown [#955](https://github.com/openshift/cluster-authentication-operator/pull/955)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#957](https://github.com/openshift/cluster-authentication-operator/pull/957)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#954](https://github.com/openshift/cluster-authentication-operator/pull/954)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: implement UpdateKMSEncryptionStatus [#953](https://github.com/openshift/cluster-authentication-operator/pull/953)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use AuthenticationInterface instead of Clientset [#952](https://github.com/openshift/cluster-authentication-operator/pull/952)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro authenticationEncryptionStatusProvider [#951](https://github.com/openshift/cluster-authentication-operator/pull/951)
* NO-JIRA: kms to kms key identifier check [#941](https://github.com/openshift/cluster-authentication-operator/pull/941)
* NO-JIRA: Bump library-go to sync [#948](https://github.com/openshift/cluster-authentication-operator/pull/948)
* [CNTRLPLANE-3234](https://issues.redhat.com/browse/CNTRLPLANE-3234): wire KMS health reporter status writer [#947](https://github.com/openshift/cluster-authentication-operator/pull/947)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/6a43170712f2da9405235824ceea3dd531570642...df5510986bb1d27b8ff10fe02cfc118fabc706d4)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/f393f54229e6c3ae74c35ae72012af92d31c03d3)
* [OCPBUGS-99660](https://issues.redhat.com/browse/OCPBUGS-99660): Fix VPA checkpoint overwrite bug [#433](https://github.com/openshift/kubernetes-autoscaler/pull/433)
* [OCPBUGS-92799](https://issues.redhat.com/browse/OCPBUGS-92799): UPSTREAM: 10001: chore(clusterapi): add machine phase check for failed machines [#430](https://github.com/openshift/kubernetes-autoscaler/pull/430)
* [AUTOSCALE-637](https://issues.redhat.com/browse/AUTOSCALE-637): Fix VPA E2E vendoring [#429](https://github.com/openshift/kubernetes-autoscaler/pull/429)
* [AUTOSCALE-555](https://issues.redhat.com/browse/AUTOSCALE-555): adding openshift provider [#417](https://github.com/openshift/kubernetes-autoscaler/pull/417)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/5313828166550a946438f683333450d7b06942e9...f393f54229e6c3ae74c35ae72012af92d31c03d3)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/e48fe1179ad671757b5a40688e2d125c1f326e8b)
* NO-JIRA: Add /release-chores chore cycle skill [#382](https://github.com/openshift/cluster-autoscaler-operator/pull/382)
* [OCPBUGS-100034](https://issues.redhat.com/browse/OCPBUGS-100034): Dump kube RBAC proxy and do metrics endpoint authn & authz in process [#381](https://github.com/openshift/cluster-autoscaler-operator/pull/381)
* [AUTOSCALE-642](https://issues.redhat.com/browse/AUTOSCALE-642): Release chores 5.0 [#380](https://github.com/openshift/cluster-autoscaler-operator/pull/380)
* NO-JIRA: add coderabbit configuration file [#375](https://github.com/openshift/cluster-autoscaler-operator/pull/375)
* NO-JIRA: update owners file with autoscale team members [#379](https://github.com/openshift/cluster-autoscaler-operator/pull/379)
* [AUTOSCALE-555](https://issues.redhat.com/browse/AUTOSCALE-555): change default cloud provider to openshift [#368](https://github.com/openshift/cluster-autoscaler-operator/pull/368)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/f8fc286e8fe102766b191410e66dfc2554bbe17f...e48fe1179ad671757b5a40688e2d125c1f326e8b)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/ce1bd1f1ff5eb9335f13fa3839add119bb51f946)
* [OCPBUGS-105455](https://issues.redhat.com/browse/OCPBUGS-105455): Fix infinite reconciliation loop in EnsureMirrorConfig [#641](https://github.com/openshift/cluster-baremetal-operator/pull/641)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Mount IDMS mirror config into machine-os-images init container [#636](https://github.com/openshift/cluster-baremetal-operator/pull/636)
* [OCPBUGS-100033](https://issues.redhat.com/browse/OCPBUGS-100033): Migrate metrics from kube-rbac-proxy sidecar to controller-runtime's SecureServing [#638](https://github.com/openshift/cluster-baremetal-operator/pull/638)
* [OCPBUGS-66101](https://issues.redhat.com/browse/OCPBUGS-66101): set Progressing=True during cluster update [#599](https://github.com/openshift/cluster-baremetal-operator/pull/599)
* [OCPQE-32094](https://issues.redhat.com/browse/OCPQE-32094): Address review feedback from PR #622 [#637](https://github.com/openshift/cluster-baremetal-operator/pull/637)
* [METAL-1922](https://issues.redhat.com/browse/METAL-1922): Bump BMO to latest downstream main branch, update the supported TLS groups for BMO [#639](https://github.com/openshift/cluster-baremetal-operator/pull/639)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add host_fw_components tests to CBO test extension [#622](https://github.com/openshift/cluster-baremetal-operator/pull/622)
* [METAL-1795](https://issues.redhat.com/browse/METAL-1795): Add TLS group/curve support [#632](https://github.com/openshift/cluster-baremetal-operator/pull/632)
* [OCPBUGS-99278](https://issues.redhat.com/browse/OCPBUGS-99278): Apply cluster TLS profile to ironic-proxy container [#633](https://github.com/openshift/cluster-baremetal-operator/pull/633)
* [OCPBUGS-99220](https://issues.redhat.com/browse/OCPBUGS-99220): static-ip-manager should be optional [#631](https://github.com/openshift/cluster-baremetal-operator/pull/631)
* [OCPBUGS-66101](https://issues.redhat.com/browse/OCPBUGS-66101): Set Progressing=True during cluster update [#629](https://github.com/openshift/cluster-baremetal-operator/pull/629)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add nic_validation OTE test [#627](https://github.com/openshift/cluster-baremetal-operator/pull/627)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/0d634647457a992eb69e140e4e22cd159986b397...ce1bd1f1ff5eb9335f13fa3839add119bb51f946)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/7552a21762cb9fed2e8e2a7b35975b52cb08ddb5)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434): add gh-summary target to download manifests from GitHub [#306](https://github.com/openshift/cluster-api/pull/306)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434): Generating manifests-summary [#305](https://github.com/openshift/cluster-api/pull/305)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): Exclude unsupported CAPI CRDs and scope ClusterRole [#304](https://github.com/openshift/cluster-api/pull/304)
* ๐ OCPCLOUD-3598: Merge https://github.com/kubernetes-sigs/cluster-api:v1.13.4 (27f4644) into main [#298](https://github.com/openshift/cluster-api/pull/298)
* [Full changelog](https://github.com/openshift/cluster-api/compare/75dfb8c5ee880caacb736841eb9954a0be75567c...7552a21762cb9fed2e8e2a7b35975b52cb08ddb5)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/5afa8634c5bd26c8ed12dbecb0c31e79ed2fb39c)
* [OCPBUGS-85063](https://issues.redhat.com/browse/OCPBUGS-85063): Fix CredentialsRequest capability annotations [#630](https://github.com/openshift/cluster-capi-operator/pull/630)
* [OCPBUGS-104496](https://issues.redhat.com/browse/OCPBUGS-104496): aws: use capa-controller-manager as service account [#644](https://github.com/openshift/cluster-capi-operator/pull/644)
* [OCPCLOUD-3513](https://issues.redhat.com/browse/OCPCLOUD-3513): Generate the manifests summary [#643](https://github.com/openshift/cluster-capi-operator/pull/643)
* [OCPCLOUD-2664](https://issues.redhat.com/browse/OCPCLOUD-2664): Aggregate controller statuses in clusteroperator controller [#574](https://github.com/openshift/cluster-capi-operator/pull/574)
* [OCPCLOUD-3647](https://issues.redhat.com/browse/OCPCLOUD-3647): Consolidate install-time object processing in toBoxcutterRevision [#633](https://github.com/openshift/cluster-capi-operator/pull/633)
* NO-JIRA: resolve placeholder version for k8s.io/autoscaler APIs [#642](https://github.com/openshift/cluster-capi-operator/pull/642)
* [OCPBUGS-100143](https://issues.redhat.com/browse/OCPBUGS-100143): e2e: skip CRD Compatibility Checker tests on External topology clusters [#638](https://github.com/openshift/cluster-capi-operator/pull/638)
* NO-JIRA: go.mod: pin k8s.io/cri-streaming to v0.36.2 [#639](https://github.com/openshift/cluster-capi-operator/pull/639)
* [OCPBUGS-100246](https://issues.redhat.com/browse/OCPBUGS-100246): Fix e2es on CAPI-native clusters [#641](https://github.com/openshift/cluster-capi-operator/pull/641)
* [OCPCLOUD-3571](https://issues.redhat.com/browse/OCPCLOUD-3571): Add OTE e2e tests for ClusterAPIMachineManagementAWS feature gate [#613](https://github.com/openshift/cluster-capi-operator/pull/613)
* [OCPCLOUD-3538](https://issues.redhat.com/browse/OCPCLOUD-3538), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): manifests-gen: enable KRM plugins and add exclude/rename-resources transformers [#621](https://github.com/openshift/cluster-capi-operator/pull/621)
* [OCPBUGS-84321](https://issues.redhat.com/browse/OCPBUGS-84321): ClusterAPIMachineManagement: capi-controllers: excessive restarts of during cluster installation [#614](https://github.com/openshift/cluster-capi-operator/pull/614)
* [OCPCLOUD-3507](https://issues.redhat.com/browse/OCPCLOUD-3507): Add OTE e2e tests for ClusterAPIMachineManagement feature gate [#606](https://github.com/openshift/cluster-capi-operator/pull/606)
* NO-JIRA: Fix buildComponentList godoc [#632](https://github.com/openshift/cluster-capi-operator/pull/632)
* [CORS-4512](https://issues.redhat.com/browse/CORS-4512): aws: allow privateDNSName and assignPrimaryIPv6 field on CAPI machines in dual-stack clusters [#592](https://github.com/openshift/cluster-capi-operator/pull/592)
* [CORS-4512](https://issues.redhat.com/browse/CORS-4512): aws: set IPv6 block on AWSCluster in dual-stack clusters [#593](https://github.com/openshift/cluster-capi-operator/pull/593)
* [OCPCLOUD-3607](https://issues.redhat.com/browse/OCPCLOUD-3607): Bump K8S to 1.36 [#628](https://github.com/openshift/cluster-capi-operator/pull/628)
* [OCPCLOUD-3368](https://issues.redhat.com/browse/OCPCLOUD-3368): Adding annotations to manifests for CVO to identify [#588](https://github.com/openshift/cluster-capi-operator/pull/588)
* [OCPCLOUD-3366](https://issues.redhat.com/browse/OCPCLOUD-3366): crdcompatibility: add validation for CRDData.Type field [#625](https://github.com/openshift/cluster-capi-operator/pull/625)
* [OCPCLOUD-3542](https://issues.redhat.com/browse/OCPCLOUD-3542): Add CRD Compatibility Checker OTE e2e tests [#599](https://github.com/openshift/cluster-capi-operator/pull/599)
* [OCPBUGS-98329](https://issues.redhat.com/browse/OCPBUGS-98329): Add aggregated cluster role for extended per-provider RBAC [#623](https://github.com/openshift/cluster-capi-operator/pull/623)
* [OCPCLOUD-3539](https://issues.redhat.com/browse/OCPCLOUD-3539): add topology-aware operator for CRD Compatibility Checker [#600](https://github.com/openshift/cluster-capi-operator/pull/600)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/5fbc7d6ca9c4c06d76d0b46969a7db192dac180a...5afa8634c5bd26c8ed12dbecb0c31e79ed2fb39c)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/acd200e50f92c188279a8347f41d14fe4a96e66f)
* [OCPBUGS-100052](https://issues.redhat.com/browse/OCPBUGS-100052): Created new job to update vSphere nodes to have vsphere label [#497](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/497)
* [OCPBUGS-105409](https://issues.redhat.com/browse/OCPBUGS-105409): chore: remove AWSServiceLBNetworkSecurityGroup feature gate references [#500](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/500)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Update Required Permissions [#493](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/493)
* [OCPCLOUD-3610](https://issues.redhat.com/browse/OCPCLOUD-3610): Update to K8s 1.36.3 dependencies [#496](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/496)
* [OCPBUGS-99755](https://issues.redhat.com/browse/OCPBUGS-99755): OTE: fix AWS endpoint resolution for non-standard partitions [#494](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/494)
* [SPLAT-2713](https://issues.redhat.com/browse/SPLAT-2713): Reapply "Merge pull request #476" to bring in e2e for BYO SG for AWS NLB [#492](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/492)
* [OCPBUGS-98617](https://issues.redhat.com/browse/OCPBUGS-98617): Fixes daemonset Progressing=True logic [#490](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/490)
* Revert #476 "SPLAT-2713: Update AWS CCM e2e test module version" [#491](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/491)
* [SPLAT-2713](https://issues.redhat.com/browse/SPLAT-2713): Update AWS CCM e2e test module version [#476](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/476)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/a1fd4479e4e166f40778b10406238dd95427b26b...acd200e50f92c188279a8347f41d14fe4a96e66f)
### [cluster-config-api](https://github.com/openshift/api/tree/9d7eaabdfe055a52983e5d68860e77344c92db31)
* [STOR-3014](https://issues.redhat.com/browse/STOR-3014): Promote SELinuxMountGAReadiness to GA [#2964](https://github.com/openshift/api/pull/2964)
* Promote ExternalOIDCWithUpstreamParity to Default feature set [#2915](https://github.com/openshift/api/pull/2915)
* [STOR-2959](https://issues.redhat.com/browse/STOR-2959): Promote VolumeGroupSnapshots to GA [#2965](https://github.com/openshift/api/pull/2965)
* Move GCD to TechPreview [#2970](https://github.com/openshift/api/pull/2970)
* [OCPNODE-4521](https://issues.redhat.com/browse/OCPNODE-4521): Promote AdditionalStorageConfig feature gate to Default [#2858](https://github.com/openshift/api/pull/2858)
* [MON-4625](https://issues.redhat.com/browse/MON-4625): add support for the nvmesubsystem collector [#2960](https://github.com/openshift/api/pull/2960)
* Promote IrreconcilableMachineConfig to GA [#2929](https://github.com/openshift/api/pull/2929)
* [NE-2777](https://issues.redhat.com/browse/NE-2777), [NE-2778](https://issues.redhat.com/browse/NE-2778): Implement Gateway API management knob [#2890](https://github.com/openshift/api/pull/2890)
* Use regex instead of format help for KMS secret name validation [#2966](https://github.com/openshift/api/pull/2966)
* [OCPBUGS-74511](https://issues.redhat.com/browse/OCPBUGS-74511): Remove RouteExternalCertificate feature gate [#2962](https://github.com/openshift/api/pull/2962)
* [MON-4607](https://issues.redhat.com/browse/MON-4607): add zoneinfo to NodeExporterCollectorConfig CRD types [#2948](https://github.com/openshift/api/pull/2948)
* [AGENT-1493](https://issues.redhat.com/browse/AGENT-1493): Promote NoRegistryClusterInstall Feature to Default [#2859](https://github.com/openshift/api/pull/2859)
* [MON-4620](https://issues.redhat.com/browse/MON-4620): expose remote-write protocol version [#2958](https://github.com/openshift/api/pull/2958)
* [CORS-4417](https://issues.redhat.com/browse/CORS-4417): Add UniverseDomain field to GCPPlatformStatus [#2963](https://github.com/openshift/api/pull/2963)
* [OCPNODE-4622](https://issues.redhat.com/browse/OCPNODE-4622): Promote CRIOCredentialProviderConfig feature gate Default [#2844](https://github.com/openshift/api/pull/2844)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Promote Multi HAProxy Versions feature to default [#2947](https://github.com/openshift/api/pull/2947)
* [MON-4616](https://issues.redhat.com/browse/MON-4616): add support for dmmultipath collector [#2956](https://github.com/openshift/api/pull/2956)
* [CORS-4387](https://issues.redhat.com/browse/CORS-4387): Promote AWS DualStack to Default [#2797](https://github.com/openshift/api/pull/2797)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): Kms plugin health report clean up [#2931](https://github.com/openshift/api/pull/2931)
* [OPRUN-4705](https://issues.redhat.com/browse/OPRUN-4705): Remove NewOLMPreflightPermissionChecks FeatureGate [#2957](https://github.com/openshift/api/pull/2957)
* [SPLAT-2827](https://issues.redhat.com/browse/SPLAT-2827): Added vSphere failure domain to vcenter check [#2932](https://github.com/openshift/api/pull/2932)
* Check all hypershift variants when the featuregate is not platform specific [#2951](https://github.com/openshift/api/pull/2951)
* [OCPBUGS-80958](https://issues.redhat.com/browse/OCPBUGS-80958): NodeUID in status to detect replaced node with same name [#2821](https://github.com/openshift/api/pull/2821)
* [OPRUN-4691](https://issues.redhat.com/browse/OPRUN-4691): Promote OLMLifecycleAndCompatibility feature gate to Default [#2920](https://github.com/openshift/api/pull/2920)
* [OPNET-780](https://issues.redhat.com/browse/OPNET-780): Add BGPBasedVIPManagement feature gate and BGP VIP management fields [#2923](https://github.com/openshift/api/pull/2923)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Align with latest beta API of Vault [#2936](https://github.com/openshift/api/pull/2936)
* Update KAL to latest [#2939](https://github.com/openshift/api/pull/2939)
* [NE-2569](https://issues.redhat.com/browse/NE-2569): Promote Dynamic Configuration Manager to Default [#2788](https://github.com/openshift/api/pull/2788)
* Adapt publish kubebuilder tools to ocp5 + publish k8s v1.36 kubebuilder tools [#2941](https://github.com/openshift/api/pull/2941)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): Add KMS preflight check API to operator/v1 [#2916](https://github.com/openshift/api/pull/2916)
* [CORS-4435](https://issues.redhat.com/browse/CORS-4435): GCP Sovereign Cloud Feature Gate [#2810](https://github.com/openshift/api/pull/2810)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2813](https://github.com/openshift/api/pull/2813)
* [OCPBUGS-91634](https://issues.redhat.com/browse/OCPBUGS-91634): CAPI: Fix ImageDigestFormat validation to allow deep registry paths [#2918](https://github.com/openshift/api/pull/2918)
* Sippy timestamp filter should use Millisecond unix timestamp for proper filtering [#2928](https://github.com/openshift/api/pull/2928)
* Remove AzureClusterHostedDNSInstall Featuregate [#2902](https://github.com/openshift/api/pull/2902)
* [Full changelog](https://github.com/openshift/api/compare/d8a1748da7dce3a6292cec8d0822c2d5e1e4318b...9d7eaabdfe055a52983e5d68860e77344c92db31)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
* [OCPBUGS-104562](https://issues.redhat.com/browse/OCPBUGS-104562): Mark kube-cloud-config recreation test disruptive [#497](https://github.com/openshift/cluster-config-operator/pull/497)
* [MON-4499](https://issues.redhat.com/browse/MON-4499): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#468](https://github.com/openshift/cluster-config-operator/pull/468)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/a02c879931c6108326c0a514df0ce2e390f3536c...9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/0a98fb46580fa472b86e1aeaa96821e0db51b741)
* NO-JIRA: Fix flaky unit-test harness races and tight timeouts [#416](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/416)
* [OCPCLOUD-3611](https://issues.redhat.com/browse/OCPCLOUD-3611): Bump Kubernetes dependencies to 1.36 [#414](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/414)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/452cee8c1f4efb683fb6bcb15b61366695d98e1e...0a98fb46580fa472b86e1aeaa96821e0db51b741)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
* [STOR-3005](https://issues.redhat.com/browse/STOR-3005): Remove v1beta2 group snapshot API [#283](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/283)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#285](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/285)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/ef7a4c8b7f5c5e6cba4486dcc37f50521e7bc655...35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/c0ed09e329e9001629518604a58205e3fbe8284a)
* [OCPBUGS-86009](https://issues.redhat.com/browse/OCPBUGS-86009): Fix dns operator reporting Progressing=True on scale up [#477](https://github.com/openshift/cluster-dns-operator/pull/477)
* [NE-2817](https://issues.redhat.com/browse/NE-2817): Gate operator metrics TLS on tlsAdherence via ShouldHonorClusterTLSProfile [#484](https://github.com/openshift/cluster-dns-operator/pull/484)
* [NE-2765](https://issues.redhat.com/browse/NE-2765): Bump Kubernetes to 1.36.2 and Go to 1.26 [#483](https://github.com/openshift/cluster-dns-operator/pull/483)
* [NE-2743](https://issues.redhat.com/browse/NE-2743): Support centralized TLS security profiles for CDO metrics [#482](https://github.com/openshift/cluster-dns-operator/pull/482)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/2e6634547bd3ac0f08350bc2235447ddf06db2b2...c0ed09e329e9001629518604a58205e3fbe8284a)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/4703f217e3094d523950fb8e952d251c5375f577)
* [OCPEDGE-2118](https://issues.redhat.com/browse/OCPEDGE-2118): Fix pcs stderr handling [#1674](https://github.com/openshift/cluster-etcd-operator/pull/1674)
* [CNTRLPLANE-3460](https://issues.redhat.com/browse/CNTRLPLANE-3460): Refactor defrag controller to lower impact of defrag [#1618](https://github.com/openshift/cluster-etcd-operator/pull/1618)
* [OCPBUGS-81500](https://issues.redhat.com/browse/OCPBUGS-81500): fix: udpate healthcheck previous state only after successful operator status update [#1614](https://github.com/openshift/cluster-etcd-operator/pull/1614)
* [OCPBUGS-105357](https://issues.redhat.com/browse/OCPBUGS-105357): Fix TNF fencing skip for IPv6 bracketed stonith IPs. [#1669](https://github.com/openshift/cluster-etcd-operator/pull/1669)
* [CNTRLPLANE-3403](https://issues.redhat.com/browse/CNTRLPLANE-3403): reduce default snapshot-count to 5000 [#1666](https://github.com/openshift/cluster-etcd-operator/pull/1666)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): feat(tnf): TNF job controller framework and lifecycle management [#1655](https://github.com/openshift/cluster-etcd-operator/pull/1655)
* NO-JIRA: add ceo disruptive suite to sippy's disruptive [#1667](https://github.com/openshift/cluster-etcd-operator/pull/1667)
* [OCPBUGS-100294](https://issues.redhat.com/browse/OCPBUGS-100294): fix TNFNodeInMaintenance PromQL label mismatch [#1664](https://github.com/openshift/cluster-etcd-operator/pull/1664)
* [OCPBUGS-94106](https://issues.redhat.com/browse/OCPBUGS-94106): Add APIServer informer to EnvVarController cache sync [#1659](https://github.com/openshift/cluster-etcd-operator/pull/1659)
* [OCPBUGS-100072](https://issues.redhat.com/browse/OCPBUGS-100072): Revert 'OCPBUGS-88490: fix etcd operator deadlock when etcd-endpoints configmap is stale' [#1660](https://github.com/openshift/cluster-etcd-operator/pull/1660)
* [OCPEDGE-2094](https://issues.redhat.com/browse/OCPEDGE-2094): Add console notifications for pacemaker health events [#1654](https://github.com/openshift/cluster-etcd-operator/pull/1654)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): update TestEtcdDBScaling to also include the validation check for BackendQuotaGiB [#1656](https://github.com/openshift/cluster-etcd-operator/pull/1656)
* [OCPEDGE-2118](https://issues.redhat.com/browse/OCPEDGE-2118): Record Kubernetes events for etcd transition lifecycle [#1653](https://github.com/openshift/cluster-etcd-operator/pull/1653)
* [OCPEDGE-2707](https://issues.redhat.com/browse/OCPEDGE-2707): Add TNF Pacemaker PrometheusRule alerts [#1650](https://github.com/openshift/cluster-etcd-operator/pull/1650)
* [CNTRLPLANE-2847](https://issues.redhat.com/browse/CNTRLPLANE-2847): render: Read FeatureGate CR from rendered manifests [#1648](https://github.com/openshift/cluster-etcd-operator/pull/1648)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/831d5e6296e75b42d7cbf33fd26cd88f3b7472ea...4703f217e3094d523950fb8e952d251c5375f577)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/94cd22d000c8b8eef24dd43cd05d06544df24930)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP Universe Domain Support [#1356](https://github.com/openshift/cluster-image-registry-operator/pull/1356)
* [OCPBUGS-99257](https://issues.redhat.com/browse/OCPBUGS-99257): Improve GCS KMS encryption error handling and documentation [#1344](https://github.com/openshift/cluster-image-registry-operator/pull/1344)
* [CORENET-7355](https://issues.redhat.com/browse/CORENET-7355): Remove redundant ingress rule from image-registry netpol [#1354](https://github.com/openshift/cluster-image-registry-operator/pull/1354)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/35ad96dc9fa4ac89028e22ef624d1187a57607bd...94cd22d000c8b8eef24dd43cd05d06544df24930)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/acca9642a81370bc1a587155f7e1e7998b7c5489)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Annotate GatewayClass when istiod is available to fix startup race [#1540](https://github.com/openshift/cluster-ingress-operator/pull/1540)
* [OCPBUGS-100424](https://issues.redhat.com/browse/OCPBUGS-100424), [OCPBUGS-104205](https://issues.redhat.com/browse/OCPBUGS-104205): Harden DNS duplicate-domain ownership checks [#1543](https://github.com/openshift/cluster-ingress-operator/pull/1543)
* [OCPBUGS-99920](https://issues.redhat.com/browse/OCPBUGS-99920): Vendor sail-operator from OSSM release-3.4.1 [#1527](https://github.com/openshift/cluster-ingress-operator/pull/1527)
* [OCPBUGS-100435](https://issues.redhat.com/browse/OCPBUGS-100435): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1539](https://github.com/openshift/cluster-ingress-operator/pull/1539)
* [TRT-2874](https://issues.redhat.com/browse/TRT-2874): Revert #1513 "NE-2836: Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways" [#1537](https://github.com/openshift/cluster-ingress-operator/pull/1537)
* [NE-2833](https://issues.redhat.com/browse/NE-2833): Replace deprecated io/ioutil usage [#1531](https://github.com/openshift/cluster-ingress-operator/pull/1531)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Bump API to promote Multi HAProxy Versions feature [#1535](https://github.com/openshift/cluster-ingress-operator/pull/1535)
* [OCPBUGS-85680](https://issues.redhat.com/browse/OCPBUGS-85680): Re-fetch infraConfig on every periodic loop iteration [#1458](https://github.com/openshift/cluster-ingress-operator/pull/1458)
* [OCPBUGS-31521](https://issues.redhat.com/browse/OCPBUGS-31521): Don't publish duplicate DNS records [#1229](https://github.com/openshift/cluster-ingress-operator/pull/1229)
* [NE-2836](https://issues.redhat.com/browse/NE-2836): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1513](https://github.com/openshift/cluster-ingress-operator/pull/1513)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Support NLB protocol to configure proxy protocol and client IP preservation [#1426](https://github.com/openshift/cluster-ingress-operator/pull/1426)
* [OCPBUGS-100186](https://issues.redhat.com/browse/OCPBUGS-100186): Rename network policy in TestContainerLoggingMinLength [#1532](https://github.com/openshift/cluster-ingress-operator/pull/1532)
* [NE-2585](https://issues.redhat.com/browse/NE-2585): Bump GWAPI to v1.5.1 and Istio v1.30.1 [#1530](https://github.com/openshift/cluster-ingress-operator/pull/1530)
* [NE-2796](https://issues.redhat.com/browse/NE-2796): Respect OpenShift TLS Profiles during Istio/GatewayAPI installation [#1480](https://github.com/openshift/cluster-ingress-operator/pull/1480)
* [NE-2742](https://issues.redhat.com/browse/NE-2742): Apply cluster TLS security profile to operator metrics and canary endpoints [#1501](https://github.com/openshift/cluster-ingress-operator/pull/1501)
* [OCPBUGS-86841](https://issues.redhat.com/browse/OCPBUGS-86841): Add BackendTLSPolicy to Gateway API e2e CRD test coverage [#1523](https://github.com/openshift/cluster-ingress-operator/pull/1523)
* [CORS-4451](https://issues.redhat.com/browse/CORS-4451): GCP: Set Universe Domain [#1515](https://github.com/openshift/cluster-ingress-operator/pull/1515)
* [NE-2809](https://issues.redhat.com/browse/NE-2809): Add upgradeable logic for HAProxy version [#1517](https://github.com/openshift/cluster-ingress-operator/pull/1517)
* [OCPBUGS-99775](https://issues.redhat.com/browse/OCPBUGS-99775): Update TestHTTPHeaderBufferSize for HAProxy 3.2 response code change [#1524](https://github.com/openshift/cluster-ingress-operator/pull/1524)
* [OCPBUGS-90616](https://issues.redhat.com/browse/OCPBUGS-90616): Add GRPCRoute to Gateway API e2e CRD test coverage [#1482](https://github.com/openshift/cluster-ingress-operator/pull/1482)
* [NE-2737](https://issues.redhat.com/browse/NE-2737): Add support for TLS curves in router deployment configuration [#1478](https://github.com/openshift/cluster-ingress-operator/pull/1478)
* [NE-2764](https://issues.redhat.com/browse/NE-2764): Bump Kubernetes to 1.36.2 and Go to 1.26 [#1505](https://github.com/openshift/cluster-ingress-operator/pull/1505)
* [OCPBUGS-98310](https://issues.redhat.com/browse/OCPBUGS-98310): Bump sail-operator install library to OSSM 3.4.0 [#1508](https://github.com/openshift/cluster-ingress-operator/pull/1508)
* [NE-2219](https://issues.redhat.com/browse/NE-2219): Select HAProxy version from IngressController API [#1498](https://github.com/openshift/cluster-ingress-operator/pull/1498)
* [TRT-2793](https://issues.redhat.com/browse/TRT-2793): Revert Bump sail-operator install library to OSSM 3.4.0 [#1507](https://github.com/openshift/cluster-ingress-operator/pull/1507)
* [OCPBUGS-98310](https://issues.redhat.com/browse/OCPBUGS-98310): vendor sail-operator install library from OSSM 3.4 [#1456](https://github.com/openshift/cluster-ingress-operator/pull/1456)
* [NE-2218](https://issues.redhat.com/browse/NE-2218): Add new HAProxy 2.8 and 3.2 image references [#1499](https://github.com/openshift/cluster-ingress-operator/pull/1499)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/7b7406ee0d4bf03de360d53c9cc4a83ee14332cc...acca9642a81370bc1a587155f7e1e7998b7c5489)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/b7ff0c476291fbcbb0a98682cc833c151cdebb0c)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#2265](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2265)
* NO-JIRA: Update KMStoKMS scenario to multi provider [#2261](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2261)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#2252](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2252)
* NO-JIRA: bump library-go api and client-go [#2257](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2257)
* NO-JIRA: Add parallelism KMS OnOff Scenarios [#2251](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2251)
* NO-JIRA: Bump library-go [#2255](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2255)
* NO-JIRA: Update openshift/* [#2249](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2249)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#2248](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2248)
* [MON-4502](https://issues.redhat.com/browse/MON-4502): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#2036](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2036)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#2246](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2246)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#2247](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2247)
* [CNTRLPLANE-3861](https://issues.redhat.com/browse/CNTRLPLANE-3861): Add KMS plugin sidecar revision readiness check [#2220](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2220)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#2238](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2238)
* NO-JIRA: Add KMS key ID identifier [#2237](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2237)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use KubeAPIServersGetter instead of Clientset [#2235](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2235)
* NO-JIRA: Refactor KMS cases [#2229](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2229)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro kubeAPIServerEncryptionStatusProvider [#2230](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2230)
* NO-JIRA: Remove old test files [#2232](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2232)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2129](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2129)
* NO-JIRA: Bump library-go to sync [#2227](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2227)
* NO-JIRA: Remove old helper and assertion func [#2223](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2223)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/ec48ccc58abf89708dcdb1a477ed260d7754a17d...b7ff0c476291fbcbb0a98682cc833c151cdebb0c)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/8db74e3fe8793043d942ef1f59cce3b0a0bcc548)
* [OCPBUGS-99770](https://issues.redhat.com/browse/OCPBUGS-99770): Remove unnecessary namespace informers from kubeInformersForNamespaces [#950](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/950)
* [OCPBUGS-99770](https://issues.redhat.com/browse/OCPBUGS-99770): remove duplicate wrappings of core_getters [#952](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/952)
* [CNTRLPLANE-3778](https://issues.redhat.com/browse/CNTRLPLANE-3778): Migrate openshift-test-private kcm cases to OTE [#943](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/943)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#930](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/930)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/209d5915dc12d517be79430e4bf4e8b0f88e405b...8db74e3fe8793043d942ef1f59cce3b0a0bcc548)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#646](https://github.com/openshift/cluster-kube-scheduler-operator/pull/646)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/4d89ee063475ec33671b7f255bf6e304bb11e235...56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/cdf27353008200166f1ad754c4ade033370077ae)
* [OCPBUGS-100160](https://issues.redhat.com/browse/OCPBUGS-100160): Fix status controller unit-test teardown race [#312](https://github.com/openshift/cluster-machine-approver/pull/312)
* NO-JIRA: Bump envtest to 1.36.2 [#314](https://github.com/openshift/cluster-machine-approver/pull/314)
* [OCPCLOUD-3612](https://issues.redhat.com/browse/OCPCLOUD-3612): Bump k8s v1.36, go 1.26 [#311](https://github.com/openshift/cluster-machine-approver/pull/311)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/1ae3f157b88c167a7dbe06c36d6e55a82f7fd4f0...cdf27353008200166f1ad754c4ade033370077ae)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/a360f0b319976f1b4154dbfe2bd8cb97e1940beb)
* [MON-4548](https://issues.redhat.com/browse/MON-4548), [MON-4549](https://issues.redhat.com/browse/MON-4549), [MON-4550](https://issues.redhat.com/browse/MON-4550), [MON-4551](https://issues.redhat.com/browse/MON-4551): Enforce Thanos grpc tls parameters [#3018](https://github.com/openshift/cluster-monitoring-operator/pull/3018)
* [MON-4612](https://issues.redhat.com/browse/MON-4612): log Phase 1 dual ConfigMap/CRD configuration notice [#2995](https://github.com/openshift/cluster-monitoring-operator/pull/2995)
* [MON-4559](https://issues.redhat.com/browse/MON-4559): enable interrupts node-exporter collector via config [#2888](https://github.com/openshift/cluster-monitoring-operator/pull/2888)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3049](https://github.com/openshift/cluster-monitoring-operator/pull/3049)
* [MON-4629](https://issues.redhat.com/browse/MON-4629): support the nvmesubsystem collector in the config CRD [#3046](https://github.com/openshift/cluster-monitoring-operator/pull/3046)
* NO-JIRA: update OWNERS [#3050](https://github.com/openshift/cluster-monitoring-operator/pull/3050)
* NO-JIRA: feat: validate systemd units [#3048](https://github.com/openshift/cluster-monitoring-operator/pull/3048)
* [OCPBUGS-105438](https://issues.redhat.com/browse/OCPBUGS-105438): feat: support ogx api adoption metrics [#2984](https://github.com/openshift/cluster-monitoring-operator/pull/2984)
* [OCPBUGS-105389](https://issues.redhat.com/browse/OCPBUGS-105389): enable read-only rootfs for all containers [#3039](https://github.com/openshift/cluster-monitoring-operator/pull/3039)
* [MON-4637](https://issues.redhat.com/browse/MON-4637): implement merge logic to support the new MessageVersion field in the config CRD [#3036](https://github.com/openshift/cluster-monitoring-operator/pull/3036)
* NO-JIRA: Add test descriptions [#3037](https://github.com/openshift/cluster-monitoring-operator/pull/3037)
* [MON-4577](https://issues.redhat.com/browse/MON-4577): restrict alertmanager gossip mesh ports to same-instance pods [#3032](https://github.com/openshift/cluster-monitoring-operator/pull/3032)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3035](https://github.com/openshift/cluster-monitoring-operator/pull/3035)
* NO-JIRA: Allow to pass custom arguments to e2e test command [#3033](https://github.com/openshift/cluster-monitoring-operator/pull/3033)
* NO-JIRA: tasks: pass context to MetricsServerTask methods instead of storing it [#3025](https://github.com/openshift/cluster-monitoring-operator/pull/3025)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3017](https://github.com/openshift/cluster-monitoring-operator/pull/3017)
* NO-JIRA: chore: update Prometheus-operator to v0.93.0 [#3010](https://github.com/openshift/cluster-monitoring-operator/pull/3010)
* [MON-4630](https://issues.redhat.com/browse/MON-4630): support the dmmultipath collector in the config CRD [#3015](https://github.com/openshift/cluster-monitoring-operator/pull/3015)
* : OCPBUGS-91735: fix: watch cluster wide proxy changes and apply changes accordingly [#3004](https://github.com/openshift/cluster-monitoring-operator/pull/3004)
* NO-JIRA: test: make TestDocExamples and TestNetworkPolicy more stable [#3013](https://github.com/openshift/cluster-monitoring-operator/pull/3013)
* NO-JIRA: add metrics for the validating webhook [#2838](https://github.com/openshift/cluster-monitoring-operator/pull/2838)
* NO-JIRA: e2e: defer subtest resource cleanup in TestPrometheusRemoteWrite [#3016](https://github.com/openshift/cluster-monitoring-operator/pull/3016)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3014](https://github.com/openshift/cluster-monitoring-operator/pull/3014)
* NO-JIRA: chore: pin GOTOOLCHAIN in update-go-deps + update Go dependencies [#3006](https://github.com/openshift/cluster-monitoring-operator/pull/3006)
* NO-JIRA: increase golangci-lint timeout [#3011](https://github.com/openshift/cluster-monitoring-operator/pull/3011)
* [MON-4624](https://issues.redhat.com/browse/MON-4624): enable the nvmesubsystem collector by default [#3005](https://github.com/openshift/cluster-monitoring-operator/pull/3005)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#2994](https://github.com/openshift/cluster-monitoring-operator/pull/2994)
* [MON-4413](https://issues.redhat.com/browse/MON-4413): support MessageVersion v2.0 for remote-write [#2977](https://github.com/openshift/cluster-monitoring-operator/pull/2977)
* [OCPBUGS-85522](https://issues.redhat.com/browse/OCPBUGS-85522): disable kubelet Endpoints in prometheus-operator [#2931](https://github.com/openshift/cluster-monitoring-operator/pull/2931)
* NO-JIRA: test: adjust e2e tests on retention settings [#2999](https://github.com/openshift/cluster-monitoring-operator/pull/2999)
* [MON-4615](https://issues.redhat.com/browse/MON-4615): add option to disable the dmmultipath collector [#2996](https://github.com/openshift/cluster-monitoring-operator/pull/2996)
* NO-JIRA: Revert "MON-3697: use maximumStartupDurationSeconds instead of container patch" [#2982](https://github.com/openshift/cluster-monitoring-operator/pull/2982)
* [MON-4558](https://issues.redhat.com/browse/MON-4558): enable zoneinfo node-exporter collector via config [#2986](https://github.com/openshift/cluster-monitoring-operator/pull/2986)
* [OCPBUGS-98450](https://issues.redhat.com/browse/OCPBUGS-98450): fall back to kube-system/global-pull-secret for telemeter-client token [#2985](https://github.com/openshift/cluster-monitoring-operator/pull/2985)
* NO-ISSUE: Update prometheus-operator dependencies [#2966](https://github.com/openshift/cluster-monitoring-operator/pull/2966)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): manually pass features to monitoring plugin [#2987](https://github.com/openshift/cluster-monitoring-operator/pull/2987)
* [OCPBUGS-99019](https://issues.redhat.com/browse/OCPBUGS-99019): jsonnet: exclude AlertmanagerClusterFailedPeers from shipped rules [#2993](https://github.com/openshift/cluster-monitoring-operator/pull/2993)
* [MON-4523](https://issues.redhat.com/browse/MON-4523): ClusterMonitoring prometheusConfig [#2953](https://github.com/openshift/cluster-monitoring-operator/pull/2953)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/81d1a317a59d2b51ca83a282dd23b3b9563f0974...a360f0b319976f1b4154dbfe2bd8cb97e1940beb)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/2dd62add27742a41f8dd6c695b7aa43578ae023c)
* [OCPBUGS-64582](https://issues.redhat.com/browse/OCPBUGS-64582): frr-k8s: use Recreate strategy for statuscleaner deployment [#3104](https://github.com/openshift/cluster-network-operator/pull/3104)
* [OCPBUGS-98918](https://issues.redhat.com/browse/OCPBUGS-98918): Use service-ca certificates for network-check-source metrics [#3097](https://github.com/openshift/cluster-network-operator/pull/3097)
* [OCPBUGS-99460](https://issues.redhat.com/browse/OCPBUGS-99460): Fix connectivity check for nodes named with IP address [#3083](https://github.com/openshift/cluster-network-operator/pull/3083)
* [CORENET-5658](https://issues.redhat.com/browse/CORENET-5658): Bump ovn-controller CPU request to 50m to prevent CPU starvation [#3051](https://github.com/openshift/cluster-network-operator/pull/3051)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Enable Network Observability on Day 0 [#3087](https://github.com/openshift/cluster-network-operator/pull/3087)
* [CORENET-7054](https://issues.redhat.com/browse/CORENET-7054): Use TLS profile to render CLI args for deployed components [#3043](https://github.com/openshift/cluster-network-operator/pull/3043)
* [CORENET-5972](https://issues.redhat.com/browse/CORENET-5972): Consume openvswitch-ipsec systemd service for OVN IPsec deployment [#2662](https://github.com/openshift/cluster-network-operator/pull/2662)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#3089](https://github.com/openshift/cluster-network-operator/pull/3089)
* [OCPBUGS-88063](https://issues.redhat.com/browse/OCPBUGS-88063): ovn-kubernetes: Move MNP from ConfigMap to CLI flags [#3072](https://github.com/openshift/cluster-network-operator/pull/3072)
* [CNTRLPLANE-3213](https://issues.redhat.com/browse/CNTRLPLANE-3213): Enable configurable PKI for managed certificate rotation [#2958](https://github.com/openshift/cluster-network-operator/pull/2958)
* [CORENET-6581](https://issues.redhat.com/browse/CORENET-6581): Add transport label to CUDN telemetry recording rule [#2978](https://github.com/openshift/cluster-network-operator/pull/2978)
* [OCPBUGS-98619](https://issues.redhat.com/browse/OCPBUGS-98619): Bump frr-k8s MAX_FDS from 1024 to 65536 [#3054](https://github.com/openshift/cluster-network-operator/pull/3054)
* Revert "Enable Network Observability on Day 0" (#2925) [#3086](https://github.com/openshift/cluster-network-operator/pull/3086)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Enable Network Observability on Day 0 [#2925](https://github.com/openshift/cluster-network-operator/pull/2925)
* [OCPBUGS-99074](https://issues.redhat.com/browse/OCPBUGS-99074): Align frr-k8s 5.0 CRDs [#3070](https://github.com/openshift/cluster-network-operator/pull/3070)
* [CORENET-7046](https://issues.redhat.com/browse/CORENET-7046): Bump Kubernetes to 1.36.2 and OCP to 5.0 [#3017](https://github.com/openshift/cluster-network-operator/pull/3017)
* [CORENET-7125](https://issues.redhat.com/browse/CORENET-7125): iptables to nftables [#3038](https://github.com/openshift/cluster-network-operator/pull/3038)
* NO-JIRA: Refresh Reviewers & Approvers lists [#3048](https://github.com/openshift/cluster-network-operator/pull/3048)
* [OCPBUGS-62144](https://issues.redhat.com/browse/OCPBUGS-62144): Makes sure rendering for egress IP reachabilityTimeout triggers restart of ovnkube (node/control) pods [#2955](https://github.com/openshift/cluster-network-operator/pull/2955)
* [CORENET-7267](https://issues.redhat.com/browse/CORENET-7267): Add pre-merge and custom checks to CodeRabbit configuration [#3037](https://github.com/openshift/cluster-network-operator/pull/3037)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/d46aa4c5f37dba622ee78279cedfdf2775324fe1...2dd62add27742a41f8dd6c695b7aa43578ae023c)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/262afdc915c507916082a6d3f658530bb6d1f149)
* [CNF-26546](https://issues.redhat.com/browse/CNF-26546): tuned:irqs: set `default_smp_affinity` using `irqaffinity=` [#1572](https://github.com/openshift/cluster-node-tuning-operator/pull/1572)
* [CNF-20633](https://issues.redhat.com/browse/CNF-20633): Enable nohz_full and skew_tick by default [#1564](https://github.com/openshift/cluster-node-tuning-operator/pull/1564)
* [OCPBUGS-98060](https://issues.redhat.com/browse/OCPBUGS-98060): BUG-FIX Latency Test [#1566](https://github.com/openshift/cluster-node-tuning-operator/pull/1566)
* [OCPBUGS-99461](https://issues.redhat.com/browse/OCPBUGS-99461): Add missing annotations to NetworkPolicy manifests [#1569](https://github.com/openshift/cluster-node-tuning-operator/pull/1569)
* [MON-4506](https://issues.redhat.com/browse/MON-4506): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#1468](https://github.com/openshift/cluster-node-tuning-operator/pull/1468)
* [OCPBUGS-100115](https://issues.redhat.com/browse/OCPBUGS-100115): E2E: LLC: Restore uncore cache annotation to true [#1570](https://github.com/openshift/cluster-node-tuning-operator/pull/1570)
* NO-JIRA: owners: update [#1563](https://github.com/openshift/cluster-node-tuning-operator/pull/1563)
* [OCPBUGS-97809](https://issues.redhat.com/browse/OCPBUGS-97809): e2e: fix broken checks and rework netqueue tests to avoid ARM ethtool blackout flakes [#1557](https://github.com/openshift/cluster-node-tuning-operator/pull/1557)
* [OCPBUGS-98915](https://issues.redhat.com/browse/OCPBUGS-98915): E2E: LLC: Pass fresh ctx variable to DeferCleanup functions [#1562](https://github.com/openshift/cluster-node-tuning-operator/pull/1562)
* [CNF-23471](https://issues.redhat.com/browse/CNF-23471): Dedicate cpus for dpdk vswitch [#1546](https://github.com/openshift/cluster-node-tuning-operator/pull/1546)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/35d8129e2d0ebaf0a76f4b93d22387234bf4acac...262afdc915c507916082a6d3f658530bb6d1f149)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/228ec940921e4443b2724ef512c0d211d4a38ba7)
* NO-ISSUE: Add dependabot configuration [#225](https://github.com/openshift/cluster-olm-operator/pull/225)
* [OPRUN-4665](https://issues.redhat.com/browse/OPRUN-4665): Update k8s dependencies from v0.35.1 to v0.36.2 and OpenShift dependencies to latest [#217](https://github.com/openshift/cluster-olm-operator/pull/217)
* [OCPBUGS-95475](https://issues.redhat.com/browse/OCPBUGS-95475): chore: bump containerd to 1.7.33 [#223](https://github.com/openshift/cluster-olm-operator/pull/223)
* [OPRUN-4676](https://issues.redhat.com/browse/OPRUN-4676): support service account deprecation for OCP 5.0 [#222](https://github.com/openshift/cluster-olm-operator/pull/222)
* [OPRUN-4696](https://issues.redhat.com/browse/OPRUN-4696): fix upgrade block message and add 5.0 cluster unit tests [#216](https://github.com/openshift/cluster-olm-operator/pull/216)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#220](https://github.com/openshift/cluster-olm-operator/pull/220)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/795384212aa1ec66d3c176b33bd7ecc6a38fd560...228ec940921e4443b2724ef512c0d211d4a38ba7)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/08aa4a0a1b406a09f23d9f140eeeb35c95024d68)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#752](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/752)
* [OCPBUGS-98618](https://issues.redhat.com/browse/OCPBUGS-98618): Add HostToContainer mountPropagation to node-pullsecrets volume mount [#744](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/744)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#747](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/747)
* NO-JIRA: bump library-go api and client-go [#746](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/746)
* Revert "NO-JIRA: Disable WatchList feature gate due to the missing support of Project watch" [#681](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/681)
* NO-JIRA: Bump library-go [#745](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/745)
* NO-JIRA: Update openshift/* [#742](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/742)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#741](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/741)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#739](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/739)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#740](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/740)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#737](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/737)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: implement UpdateKMSEncryptionStatus [#736](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/736)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use OpenShiftAPIServerInterface instead of Clientset [#735](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/735)
* NO-JIRA: kms to kms key identifier check [#728](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/728)
* [OCPBUGS-87507](https://issues.redhat.com/browse/OCPBUGS-87507): Updating ose-cluster-openshift-apiserver-operator-container image to be consistent with ART for 5.0 [#705](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/705)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro openShiftAPIServerEncryptionStatusProvider [#734](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/734)
* NO-JIRA: Bump library-go to sync [#732](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/732)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/0296e27fd2034cf4365b97b4c1a103b3be4a6298...08aa4a0a1b406a09f23d9f140eeeb35c95024d68)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/469bbf211d35eee0df4422bda7e9e600b080f0f2)
* [OCPBUGS-87476](https://issues.redhat.com/browse/OCPBUGS-87476): Updating ose-cluster-policy-controller-container image to be consistent with ART for 5.0 [#188](https://github.com/openshift/cluster-policy-controller/pull/188)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Bump to Kube v1.36.2 [#197](https://github.com/openshift/cluster-policy-controller/pull/197)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/050c1ee6aeb0838daf75858fd853cca1e0098fa9...469bbf211d35eee0df4422bda7e9e600b080f0f2)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/02c0f0733d50d6ad2b4805eb5b69a058ee6b0840)
* [OCPSTRAT-3578](https://issues.redhat.com/browse/OCPSTRAT-3578): Add NetworkPolicy manifests for openshift-cluster-samples-operator namespace [#703](https://github.com/openshift/cluster-samples-operator/pull/703)
* [OCPBUGS-105319](https://issues.redhat.com/browse/OCPBUGS-105319): update kubernetes api to v0.36.3 [#704](https://github.com/openshift/cluster-samples-operator/pull/704)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/eee95babd52053191e29355108f7daf149dfbf8f...02c0f0733d50d6ad2b4805eb5b69a058ee6b0840)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/0b4e97f2a11c7ebdb0ce572e9df8064007db45c0)
* [STOR-3011](https://issues.redhat.com/browse/STOR-3011): Implement CSO upgrade check and Prometheus alerts for SELnuxMount readiness, updated runbook URL [#724](https://github.com/openshift/cluster-storage-operator/pull/724)
* [OCPBUGS-101758](https://issues.redhat.com/browse/OCPBUGS-101758): Fix SELinuxMountGAReadiness on HyperShift [#721](https://github.com/openshift/cluster-storage-operator/pull/721)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#717](https://github.com/openshift/cluster-storage-operator/pull/717)
* [STOR-3056](https://issues.redhat.com/browse/STOR-3056): inject TLS adherence from API to vsphere problem detector configmap [#718](https://github.com/openshift/cluster-storage-operator/pull/718)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): NetworkPolicies should use numeric ports instead of named ports [#720](https://github.com/openshift/cluster-storage-operator/pull/720)
* [STOR-3013](https://issues.redhat.com/browse/STOR-3013): Add e2e test for SELinuxMount upgrade readiness [#715](https://github.com/openshift/cluster-storage-operator/pull/715)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#719](https://github.com/openshift/cluster-storage-operator/pull/719)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/8ac48254009fb4987bee1f3e00cbb8e4d730f545...0b4e97f2a11c7ebdb0ce572e9df8064007db45c0)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/f94dc81765de89b6610894a3994a8aa4724e9787)
* [OCPBUGS-14392](https://issues.redhat.com/browse/OCPBUGS-14392): make sync status Failure logs human-readable [#1440](https://github.com/openshift/cluster-version-operator/pull/1440)
* [OCPBUGS-79358](https://issues.redhat.com/browse/OCPBUGS-79358): pkg/cvo/egress: Disable Proxy respect on HyperShift [#1357](https://github.com/openshift/cluster-version-operator/pull/1357)
* NO-JIRA: fix(pkg/cincinnati): log the correct root CA pool size [#1413](https://github.com/openshift/cluster-version-operator/pull/1413)
* [OTA-1997](https://issues.redhat.com/browse/OTA-1997): Allow the CVO to use the agentic-skills payload image when creating proposals [#1433](https://github.com/openshift/cluster-version-operator/pull/1433)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): Register agenticrunv1alpha1 in the Runtime client scheme [#1434](https://github.com/openshift/cluster-version-operator/pull/1434)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): pkg/agenticrun/controller: Inline AgenticRun prompt, dropping the ConfigMap [#1432](https://github.com/openshift/cluster-version-operator/pull/1432)
* [TRT-2842](https://issues.redhat.com/browse/TRT-2842): Revert #1427 "OTA-1997: Allow the CVO to use the agentic-skills payload image when creating proposals." [#1431](https://github.com/openshift/cluster-version-operator/pull/1431)
* [OTA-1997](https://issues.redhat.com/browse/OTA-1997): Allow the CVO to use the agentic-skills payload image when creating proposals. [#1427](https://github.com/openshift/cluster-version-operator/pull/1427)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084), [OTA-2097](https://issues.redhat.com/browse/OTA-2097): pkg/agenticrun/controller: Additional logging to AgenticRun CRD detection [#1428](https://github.com/openshift/cluster-version-operator/pull/1428)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): Conditionally deploy console plugin when AgenticRun CRD is present [#1425](https://github.com/openshift/cluster-version-operator/pull/1425)
* NO-JIRA: Fix make build target cd issue [#1404](https://github.com/openshift/cluster-version-operator/pull/1404)
* [OTA-2064](https://issues.redhat.com/browse/OTA-2064): Rename Proposal API to AgenticRun [#1422](https://github.com/openshift/cluster-version-operator/pull/1422)
* [OTA-1967](https://issues.redhat.com/browse/OTA-1967): install: Drop Lightspeed CustomResourceDefinitions (Proposal, etc.) [#1412](https://github.com/openshift/cluster-version-operator/pull/1412)
* [OTA-1956](https://issues.redhat.com/browse/OTA-1956): install: Split multi-document YAML and add missing annotations [#1423](https://github.com/openshift/cluster-version-operator/pull/1423)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/b5833af1ada5a3036f60cc0c22d460908958e02a...f94dc81765de89b6610894a3994a8aa4724e9787)
### [console](https://github.com/openshift/console/tree/51d6f7452e149b4c4a51f18fe5eb519b3a16f715)
* [OCPBUGS-106132](https://issues.redhat.com/browse/OCPBUGS-106132): fix gap in data view checkbox col [#16964](https://github.com/openshift/console/pull/16964)
* [CONSOLE-5438](https://issues.redhat.com/browse/CONSOLE-5438): Expose `ResourceYAMLEditor` `onCancel` to the SDK [#16941](https://github.com/openshift/console/pull/16941)
* [OCPBUGS-105598](https://issues.redhat.com/browse/OCPBUGS-105598): Bump to @rspack/core 2.1.9 and drop "megahard" packages [#16950](https://github.com/openshift/console/pull/16950)
* [OCPBUGS-70112](https://issues.redhat.com/browse/OCPBUGS-70112): Add Cache-Control headers to console responses [#16923](https://github.com/openshift/console/pull/16923)
* [OCPBUGS-105519](https://issues.redhat.com/browse/OCPBUGS-105519): Fix flaky e2e tests missing warmupSPA [#16939](https://github.com/openshift/console/pull/16939)
* [OCPBUGS-98943](https://issues.redhat.com/browse/OCPBUGS-98943): Make developerCatalog.types matching case-insensitive [#16876](https://github.com/openshift/console/pull/16876)
* [OCPBUGS-105517](https://issues.redhat.com/browse/OCPBUGS-105517): Fix flaky search.spec.ts Playwright e2e tests [#16938](https://github.com/openshift/console/pull/16938)
* [OCPBUGS-95592](https://issues.redhat.com/browse/OCPBUGS-95592): Humanize memory and storage values in ResourceQuota display [#16874](https://github.com/openshift/console/pull/16874)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): follow up la migration du i18next-cli [#16926](https://github.com/openshift/console/pull/16926)
* [OCPBUGS-67295](https://issues.redhat.com/browse/OCPBUGS-67295): Fix icon display for duplicate operator names from different catalogs [#16898](https://github.com/openshift/console/pull/16898)
* [OCPBUGS-81511](https://issues.redhat.com/browse/OCPBUGS-81511): Remove unscoped CSV watch from ClusterNotUpgradeableAlert [#16904](https://github.com/openshift/console/pull/16904)
* NO-JIRA: Add ReadWriteOncePod support for Cinder CSI driver [#16870](https://github.com/openshift/console/pull/16870)
* [OTA-2035](https://issues.redhat.com/browse/OTA-2035): Address ProdSec findings for OLS Helper Buttons [#16910](https://github.com/openshift/console/pull/16910)
* [CONSOLE-5414](https://issues.redhat.com/browse/CONSOLE-5414): Migrate dev-console Cypress tests to Playwright (batch 2) [#16741](https://github.com/openshift/console/pull/16741)
* [OCPBUGS-105314](https://issues.redhat.com/browse/OCPBUGS-105314): Fix xterm ResizeObserver crash on uninitialized dimensions [#16918](https://github.com/openshift/console/pull/16918)
* [OCPBUGS-105273](https://issues.redhat.com/browse/OCPBUGS-105273): Fix nested interactive controls on Search page [#16914](https://github.com/openshift/console/pull/16914)
* [CONSOLE-5228](https://issues.redhat.com/browse/CONSOLE-5228): re-enable eslint rules and autofix + bump prettier [#16915](https://github.com/openshift/console/pull/16915)
* [OCPBUGS-105318](https://issues.redhat.com/browse/OCPBUGS-105318): Fix node-groups-filter test to use correct page-heading test ID [#16912](https://github.com/openshift/console/pull/16912)
* [OCPBUGS-102342](https://issues.redhat.com/browse/OCPBUGS-102342): Dismiss Quick Start drawer in Playwright e2e tests [#16903](https://github.com/openshift/console/pull/16903)
* [OCPBUGS-90514](https://issues.redhat.com/browse/OCPBUGS-90514): Fix CVE-2026-12143 form-data CRLF injection [#16865](https://github.com/openshift/console/pull/16865)
* NO-JIRA: Prepare for publishing new 4.23 prerelease plugin SDK packages [#16905](https://github.com/openshift/console/pull/16905)
* [CONSOLE-5424](https://issues.redhat.com/browse/CONSOLE-5424): Add minimize action for toast notifications [#16762](https://github.com/openshift/console/pull/16762)
* [CONSOLE-5118](https://issues.redhat.com/browse/CONSOLE-5118): Improve AI assessment prompts [#16880](https://github.com/openshift/console/pull/16880)
* [CONSOLE-5241](https://issues.redhat.com/browse/CONSOLE-5241): Migrate knative-ci.feature Cypress tests to Playwright [#16658](https://github.com/openshift/console/pull/16658)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Bump @openshift/dynamic-plugin-sdk to 9.1.0 [#16897](https://github.com/openshift/console/pull/16897)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Add rspack native bindings for linux/s390x and linux/ppc64le [#16890](https://github.com/openshift/console/pull/16890)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes across multiple test suites [#16881](https://github.com/openshift/console/pull/16881)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Increase Playwright CI retries and abort after 10 failures [#16887](https://github.com/openshift/console/pull/16887)
* [OCPBUGS-99434](https://issues.redhat.com/browse/OCPBUGS-99434): Show toast notification for invalid Helm Chart repositories [#16792](https://github.com/openshift/console/pull/16792)
* [CONSOLE-5417](https://issues.redhat.com/browse/CONSOLE-5417): Migrate dev-console Cypress tests to Playwright (batch 4) [#16767](https://github.com/openshift/console/pull/16767)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Align Console useResolvedExtensions hook with upstream plugin SDK [#16815](https://github.com/openshift/console/pull/16815)
* [OCPBUGS-99491](https://issues.redhat.com/browse/OCPBUGS-99491): Fix Installed Operators table row cells ignoring column management [#16817](https://github.com/openshift/console/pull/16817)
* [CONSOLE-5439](https://issues.redhat.com/browse/CONSOLE-5439): Migrate to eslint 9 [#16878](https://github.com/openshift/console/pull/16878)
* [CONSOLE-5409](https://issues.redhat.com/browse/CONSOLE-5409): Add Playwright e2e test for operator lifecycle metadata UI [#16701](https://github.com/openshift/console/pull/16701)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Replace page.locator with getByTestId in Playwright tests [#16873](https://github.com/openshift/console/pull/16873)
* [OCPBUGS-90080](https://issues.redhat.com/browse/OCPBUGS-90080): Validate chart URL in /api/helm/verify to prevent SSRF [#16786](https://github.com/openshift/console/pull/16786)
* [CONSOLE-5400](https://issues.redhat.com/browse/CONSOLE-5400): Make Node management enhancements flagged by OpenShift 5 [#16797](https://github.com/openshift/console/pull/16797)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes and CI reliability [#16863](https://github.com/openshift/console/pull/16863)
* NO-JIRA: Remove generated plugin manifest JSON schema files [#16875](https://github.com/openshift/console/pull/16875)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): i18next-cli migration follow up [#16864](https://github.com/openshift/console/pull/16864)
* [RFE-4925](https://issues.redhat.com/browse/RFE-4925): Fix inconsistent Search page filter default (use Name) [#16601](https://github.com/openshift/console/pull/16601)
* [HELM-763](https://issues.redhat.com/browse/HELM-763): Add secrets for Helm release upgrade [#16787](https://github.com/openshift/console/pull/16787)
* [CONSOLE-5397](https://issues.redhat.com/browse/CONSOLE-5397): Log perspective overrides when starting Bridge [#16838](https://github.com/openshift/console/pull/16838)
* NO-JIRA: Remove plugin sdk build from `yarn dev` [#16850](https://github.com/openshift/console/pull/16850)
* [OCPBUGS-33836](https://issues.redhat.com/browse/OCPBUGS-33836): quickstart page i18n misses (Fix Quick Starts i18n bundle lookup for zh-CN) [#16819](https://github.com/openshift/console/pull/16819)
* [OCPBUGS-99418](https://issues.redhat.com/browse/OCPBUGS-99418): Bump protobufjs to 7.6.5 to fix CVE-2026-59877, CVE-2026-48712, CVE-2026-41242 [#16813](https://github.com/openshift/console/pull/16813)
* [OCPBUGS-84564](https://issues.redhat.com/browse/OCPBUGS-84564): remove block volume mode in case of ocs-storagecluster-ceph-nfs [#16397](https://github.com/openshift/console/pull/16397)
* [OCPBUGS-86280](https://issues.redhat.com/browse/OCPBUGS-86280): Guard against null plugin route components [#16587](https://github.com/openshift/console/pull/16587)
* [CONSOLE-5434](https://issues.redhat.com/browse/CONSOLE-5434): Replace Popper with PF components [#16831](https://github.com/openshift/console/pull/16831)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#16804](https://github.com/openshift/console/pull/16804)
* NO-JIRA: Make regular notification icon outlined by default [#16811](https://github.com/openshift/console/pull/16811)
* [OCPBUGS-94168](https://issues.redhat.com/browse/OCPBUGS-94168): Fix CVE-2026-13149 brace-expansion DoS vulnerability [#16812](https://github.com/openshift/console/pull/16812)
* [OCPBUGS-72369](https://issues.redhat.com/browse/OCPBUGS-72369): i18n format missing for Request/limit unit labels on deploy image page [#16805](https://github.com/openshift/console/pull/16805)
* [OCPBUGS-57309](https://issues.redhat.com/browse/OCPBUGS-57309): '0 B' is shown on details page when create pvc with 'EiB' unit [#16800](https://github.com/openshift/console/pull/16800)
* [OCPBUGS-77379](https://issues.redhat.com/browse/OCPBUGS-77379): Incorrect translations for 'CatalogSources' and 'OperatorGroups' in lโฆ [#16801](https://github.com/openshift/console/pull/16801)
* [OCPBUGS-99475](https://issues.redhat.com/browse/OCPBUGS-99475): Fix virtualized table row overlap after react-virtualized 9.22.6 upgrade [#16798](https://github.com/openshift/console/pull/16798)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): migrate to `i18next-cli` [#16796](https://github.com/openshift/console/pull/16796)
* NO-JIRA: Move jest config out of package.json [#16799](https://github.com/openshift/console/pull/16799)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Migrate to rspack [#16761](https://github.com/openshift/console/pull/16761)
* [OCPBUGS-99226](https://issues.redhat.com/browse/OCPBUGS-99226): Disable Knative e2e cypress test [#16782](https://github.com/openshift/console/pull/16782)
* [OCPBUGS-99052](https://issues.redhat.com/browse/OCPBUGS-99052): recover from reverse proxy panic on browser disconnect [#16776](https://github.com/openshift/console/pull/16776)
* [OTA-2066](https://issues.redhat.com/browse/OTA-2066): AIA mitigations [#16763](https://github.com/openshift/console/pull/16763)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Clean up Console extension code reference processing [#16115](https://github.com/openshift/console/pull/16115)
* [CONSOLE-5426](https://issues.redhat.com/browse/CONSOLE-5426): remove GraphQL proxy endpoint [#16769](https://github.com/openshift/console/pull/16769)
* [OCPBUGS-79520](https://issues.redhat.com/browse/OCPBUGS-79520): Fix kebab actions on Installed Operators list page [#16682](https://github.com/openshift/console/pull/16682)
* [HELM-731](https://issues.redhat.com/browse/HELM-731): Upgrade helm in console [#16607](https://github.com/openshift/console/pull/16607)
* [OCPBUGS-98489](https://issues.redhat.com/browse/OCPBUGS-98489): CVE-2026-59869 bump js-yaml [#16760](https://github.com/openshift/console/pull/16760)
* [CONSOLE-5415](https://issues.redhat.com/browse/CONSOLE-5415), [OCPBUGS-94037](https://issues.redhat.com/browse/OCPBUGS-94037): Bump react-router to ~7.18.1 [#16726](https://github.com/openshift/console/pull/16726)
* NO-ISSUE: Add empty Prow techPreview e2e entrypoint scripts [#16766](https://github.com/openshift/console/pull/16766)
* NO-ISSUE: Match operator lifecycle versions by major.minor only [#16698](https://github.com/openshift/console/pull/16698)
* [CONSOLE-3956](https://issues.redhat.com/browse/CONSOLE-3956): Replace custom Shortcut components with PF ShortcutGrid [#16207](https://github.com/openshift/console/pull/16207)
* NO-ISSUE: Skip OLMv0-specific e2e tests when techPreview is enabled [#16759](https://github.com/openshift/console/pull/16759)
* [CONSOLE-5423](https://issues.redhat.com/browse/CONSOLE-5423): Add rspack support for dynamic plugins [#16752](https://github.com/openshift/console/pull/16752)
* [CONSOLE-5421](https://issues.redhat.com/browse/CONSOLE-5421): Rename "Self-support" to "Unsupported" and stack support phase date [#16742](https://github.com/openshift/console/pull/16742)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix flaky Playwright e2e tests caused by OAuth redirect timing [#16740](https://github.com/openshift/console/pull/16740)
* [CONSOLE-5306](https://issues.redhat.com/browse/CONSOLE-5306): Surface Playwright report link in Prow Spyglass [#16743](https://github.com/openshift/console/pull/16743)
* [OCPBUGS-50016](https://issues.redhat.com/browse/OCPBUGS-50016), [OCPBUGS-86587](https://issues.redhat.com/browse/OCPBUGS-86587): Bump to PF 6.6.0 [#16750](https://github.com/openshift/console/pull/16750)
* [OCPBUGS-88715](https://issues.redhat.com/browse/OCPBUGS-88715): Bump follow-redirects from 1.15.3 to 1.16.0 to remediate CVE-2026-40895 [#16590](https://github.com/openshift/console/pull/16590)
* And 11 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/bc58d0788f862ae05af0a910c701fd47b16b791b...51d6f7452e149b4c4a51f18fe5eb519b3a16f715)
### [console-operator](https://github.com/openshift/console-operator/tree/080a8a9d3310799313d897c9cd61ad9ef2f8c7c8)
* [OCPBUGS-77026](https://issues.redhat.com/browse/OCPBUGS-77026): DNS optimization, add trailing dots [#1112](https://github.com/openshift/console-operator/pull/1112)
* [OCPBUGS-95602](https://issues.redhat.com/browse/OCPBUGS-95602): Add OpenShift Quickstart for JBoss EAP 8 [#932](https://github.com/openshift/console-operator/pull/932)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): Revert "TRT-2858: Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console"" [#1205](https://github.com/openshift/console-operator/pull/1205)
* [OSDOCS-20110](https://issues.redhat.com/browse/OSDOCS-20110): Add Helm 3 CLI download links alongside Helm 4 [#1197](https://github.com/openshift/console-operator/pull/1197)
* [OCPBUGS-99943](https://issues.redhat.com/browse/OCPBUGS-99943): set API-server-defaulted fields on deployment specs to prevent excessive update events [#1201](https://github.com/openshift/console-operator/pull/1201)
* [CONSOLE-5431](https://issues.redhat.com/browse/CONSOLE-5431): Add allow-all NetworkPolicy to openshift-console namespace [#1199](https://github.com/openshift/console-operator/pull/1199)
* [TRT-2858](https://issues.redhat.com/browse/TRT-2858): Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console" [#1200](https://github.com/openshift/console-operator/pull/1200)
* [CONSOLE-5432](https://issues.redhat.com/browse/CONSOLE-5432): Add NetworkPolicy manifests for openshift-console-operator namespace [#1198](https://github.com/openshift/console-operator/pull/1198)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#1196](https://github.com/openshift/console-operator/pull/1196)
* NO-JIRA: Revert "Merge pull request #1170 from logonoff/http2" [#1194](https://github.com/openshift/console-operator/pull/1194)
* [CONSOLE-5433](https://issues.redhat.com/browse/CONSOLE-5433): Add default-deny NetworkPolicy for openshift-console-user-settings namespace [#1195](https://github.com/openshift/console-operator/pull/1195)
* [OCPBUGS-93982](https://issues.redhat.com/browse/OCPBUGS-93982): gate Progressing on version transition and operand rollout status [#1188](https://github.com/openshift/console-operator/pull/1188)
* [HELM-639](https://issues.redhat.com/browse/HELM-639): Update Helm download manifests for Helm 3 and Helm 4. [#1175](https://github.com/openshift/console-operator/pull/1175)
* [CONSOLE-5122](https://issues.redhat.com/browse/CONSOLE-5122): Multi-domain console route, ConfigMap, and OAuth support [#1184](https://github.com/openshift/console-operator/pull/1184)
* [OCPBUGS-67134](https://issues.redhat.com/browse/OCPBUGS-67134): add grace period before reporting Available=False [#1179](https://github.com/openshift/console-operator/pull/1179)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console-operator/compare/da112ceea6da057747900b7e39a88ada9e320e9b...080a8a9d3310799313d897c9cd61ad9ef2f8c7c8)
### [coredns](https://github.com/openshift/coredns/tree/37aaba896e97f4b9a091aab6d36f2213b8854474)
* [NE-2744](https://issues.redhat.com/browse/NE-2744): UPSTREAM: 8227: fix(tls): use Go TLS defaults [#194](https://github.com/openshift/coredns/pull/194)
* [OCPBUGS-87352](https://issues.redhat.com/browse/OCPBUGS-87352): Updating coredns-container image to be consistent with ART for 5.0 [#189](https://github.com/openshift/coredns/pull/189)
* [Full changelog](https://github.com/openshift/coredns/compare/97f7cc327ab5df7d6da38137b7be338efa9a3551...37aaba896e97f4b9a091aab6d36f2213b8854474)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/aa9a8100e87ff13abf4dd6343c84c9f4948debef)
* [OCPBUGS-96822](https://issues.redhat.com/browse/OCPBUGS-96822): Bump golang.org/x/net to v0.55.0 [#405](https://github.com/openshift/cloud-provider-openstack/pull/405)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c...aa9a8100e87ff13abf4dd6343c84c9f4948debef)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa)
* [OCPBUGS-97795](https://issues.redhat.com/browse/OCPBUGS-97795): Bump golang.org/x/crypto to v0.53.0 [#197](https://github.com/openshift/csi-driver-nfs/pull/197)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/a40a98e2027a63e2a8ddd3589ee3c5142104dbd6...beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa)
### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/3fd668b3f07dd382e5c7b6239d50f7988f652e64)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v4.12.0 for OCP 5.0 [#110](https://github.com/openshift/csi-external-attacher/pull/110)
* [Full changelog](https://github.com/openshift/csi-external-attacher/compare/96ebfa733c06c3398555d164c788e310908fecf6...3fd668b3f07dd382e5c7b6239d50f7988f652e64)
### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v6.3.0 for OCP 5.0 [#146](https://github.com/openshift/csi-external-provisioner/pull/146)
* [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/bdf440fab8a48e4b76cf0902ad5ba17a20881a8b...7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.2.1 for OCP 5.0 [#198](https://github.com/openshift/csi-external-resizer/pull/198)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/c608adfc7e82c7c59221bb9d22642a1902cace43...14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
* [OCPBUGS-99009](https://issues.redhat.com/browse/OCPBUGS-99009): [external-snapshotter] SnapshotContentObjectDeleteError event fired when VolumeSnapshotContent is already deleted [#226](https://github.com/openshift/csi-external-snapshotter/pull/226)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8...a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/463dc553ebb04df192d573c5a1612dcb50cb1f52)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.19.0 for OCP 5.0 [#94](https://github.com/openshift/csi-livenessprobe/pull/94)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/f649d2c76f2484b73c70007801eb81ab4be63635...463dc553ebb04df192d573c5a1612dcb50cb1f52)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/5766960d82ffb9ef84d15e903ae57d0a6781ef11)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.17.0 for OCP 5.0 [#108](https://github.com/openshift/csi-node-driver-registrar/pull/108)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/02d5345005aeb6aac2277818937501cdd1a3a88e...5766960d82ffb9ef84d15e903ae57d0a6781ef11)
### [docker-registry](https://github.com/openshift/image-registry/tree/a91ce6edf2c5cc08aa184c47dff79e842079c533)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP: Support Alternate Universe Domain [#474](https://github.com/openshift/image-registry/pull/474)
* [Full changelog](https://github.com/openshift/image-registry/compare/eb1b09dc465a8d53c5683da40f5d5fd306fd945a...a91ce6edf2c5cc08aa184c47dff79e842079c533)
### [driver-toolkit](https://github.com/openshift/driver-toolkit/tree/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
* [OCPBUGS-82502](https://issues.redhat.com/browse/OCPBUGS-82502): Fix e2e test duplicate output from oc run -i --rm [#198](https://github.com/openshift/driver-toolkit/pull/198)
* [Full changelog](https://github.com/openshift/driver-toolkit/compare/7ec03cbba69b4dc86ee33e313bad32ae2ea2924e...b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
* NO-JIRA: Remove dead code, drastically shrink vendored deps [#110](https://github.com/openshift/egress-router-cni/pull/110)
* NO-JIRA: Update OWNERS file [#104](https://github.com/openshift/egress-router-cni/pull/104)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/a923d37cfe033853603240f862cb907ba997cb68...7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
### [etcd, installer-etcd-artifacts](https://github.com/openshift/etcd/tree/609b11ed8fc404fb95572d7c87e3243a1206cdb7)
* DOWNSTREAM: carry: OCPBUGS-103516: Replace bbolt with patched fork to remove MADV_RANDOM [#395](https://github.com/openshift/etcd/pull/395)
* [CNTRLPLANE-3461](https://issues.redhat.com/browse/CNTRLPLANE-3461): refactor defrag to minimize database lock time [#378](https://github.com/openshift/etcd/pull/378)
* [OCPBUGS-94014](https://issues.redhat.com/browse/OCPBUGS-94014): Rebase v3.6.13 on main (5.0/4.23) [#392](https://github.com/openshift/etcd/pull/392)
* [Full changelog](https://github.com/openshift/etcd/compare/bf6c0094589afdf6c814a28c24f8f1bb5a577816...609b11ed8fc404fb95572d7c87e3243a1206cdb7)
### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/51c326465b3160124b8097953b42e44f1056da5a)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): Support setting universe domain in client options [#131](https://github.com/openshift/cloud-provider-gcp/pull/131)
* [OCPCLOUD-3592](https://issues.redhat.com/browse/OCPCLOUD-3592): Merge https://github.com/kubernetes/cloud-provider-gcp:master (b01dfd6) into main [#104](https://github.com/openshift/cloud-provider-gcp/pull/104)
* [OCPBUGS-84569](https://issues.redhat.com/browse/OCPBUGS-84569): Fix node.kubernetes.io/exclude-from-external-load-balancers on masters [#121](https://github.com/openshift/cloud-provider-gcp/pull/121)
* [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/1a542ecb49b1b26ea7ecd6344a9ebe7dbe09b6b6...51c326465b3160124b8097953b42e44f1056da5a)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/dbcbfe70efa75f192309f2d0f8daae2c6a441e90)
* [OCPCLOUD-3601](https://issues.redhat.com/browse/OCPCLOUD-3601): Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.13.0 (be0534e) into main [#300](https://github.com/openshift/cluster-api-provider-gcp/pull/300)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#299](https://github.com/openshift/cluster-api-provider-gcp/pull/299)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/ffbf9c2a410aa425c29c4628fa250d2e949b6876...dbcbfe70efa75f192309f2d0f8daae2c6a441e90)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b)
* [OCPCLOUD-3617](https://issues.redhat.com/browse/OCPCLOUD-3617): Update to Kubernetes 1.36 dependencies [#182](https://github.com/openshift/machine-api-provider-gcp/pull/182)
* [CORS-4521](https://issues.redhat.com/browse/CORS-4521): Support Alternate Universe Domain [#180](https://github.com/openshift/machine-api-provider-gcp/pull/180)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/1d098131fa7123b9793e01dcdac4d0b18b9ef1ae...91033fc5b42f58acdad7be8c89a0012f5f2c9b5b)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/049c0b96742c40fdd4384920afe17cefa5fa3d27)
* [STOR-3064](https://issues.redhat.com/browse/STOR-3064): Add Universe Domain Support (for Google Cloud Dedicated) [#126](https://github.com/openshift/gcp-pd-csi-driver/pull/126)
* [STOR-2915](https://issues.redhat.com/browse/STOR-2915): Update go.opentelemetry.io/otel and otel/sdk to v1.43.0 [#125](https://github.com/openshift/gcp-pd-csi-driver/pull/125)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/e5a04641120fdae120db1c53cbed703f1ecf77e7...049c0b96742c40fdd4384920afe17cefa5fa3d27)
### [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook/tree/4501ff2f53576c31df0511b69444e65e1eeba745)
* [OCPCLOUD-3585](https://issues.redhat.com/browse/OCPCLOUD-3585): Update gcp-workload-identity-federation-webhook to k8s 1.36 [#21](https://github.com/openshift/gcp-workload-identity-federation-webhook/pull/21)
* [Full changelog](https://github.com/openshift/gcp-workload-identity-federation-webhook/compare/a8f16141e4234fa2c9f6aeb8498622af6e4a080d...4501ff2f53576c31df0511b69444e65e1eeba745)
### [haproxy-router](https://github.com/openshift/router/tree/4b401a86dccc657a8a5254c2794a312241f40e87)
* [NE-2826](https://issues.redhat.com/browse/NE-2826): Fix staticcheck warnings across multiple packages [#815](https://github.com/openshift/router/pull/815)
* "NO-JIRA: Add AGENTS.md" [#710](https://github.com/openshift/router/pull/710)
* [NE-2829](https://issues.redhat.com/browse/NE-2829): images/router/f5: Delete F5 router Dockerfile [#826](https://github.com/openshift/router/pull/826)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Revert #825 "Make external cert validation asynchronous (v2 โ race condition fixes)" [#829](https://github.com/openshift/router/pull/829)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (v2 โ race condition fixes) [#825](https://github.com/openshift/router/pull/825)
* NO-JIRA: Add default coderabbit for the repo [#798](https://github.com/openshift/router/pull/798)
* [TRT-2841](https://issues.redhat.com/browse/TRT-2841): Revert "OCPBUGS-77056: Make external cert validation asynchronous (Resurrection)" [#824](https://github.com/openshift/router/pull/824)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (Resurrection) [#822](https://github.com/openshift/router/pull/822)
* [NE-2220](https://issues.redhat.com/browse/NE-2220): Update HAProxy RPM in the router container to 3.2.19 [#792](https://github.com/openshift/router/pull/792)
* [NE-2741](https://issues.redhat.com/browse/NE-2741): Implement TLS Curves Support for Metrics Endpoints [#811](https://github.com/openshift/router/pull/811)
* [TRT-2813](https://issues.redhat.com/browse/TRT-2813): Revert "Make external cert validation asynchronous" [#817](https://github.com/openshift/router/pull/817)
* [NE-2766](https://issues.redhat.com/browse/NE-2766): Bump Kubernetes to 1.36.2 and Go to 1.26 [#814](https://github.com/openshift/router/pull/814)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous [#745](https://github.com/openshift/router/pull/745)
* [OCPBUGS-87204](https://issues.redhat.com/browse/OCPBUGS-87204): Prevent SSRF via FQDN-typed EndpointSlices [#812](https://github.com/openshift/router/pull/812)
* [Full changelog](https://github.com/openshift/router/compare/92a1fe6420e7fa5cff3ac1e4234b866e8f742c9f...4b401a86dccc657a8a5254c2794a312241f40e87)
### [hyperkube, installer-kube-apiserver-artifacts, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/c56d0ff2dbba9f3aa73e193deea591a74b298717)
* [OCPBUGS-64847](https://issues.redhat.com/browse/OCPBUGS-64847): kubelet: don't use non-admitted pods in calculation [#2667](https://github.com/openshift/kubernetes/pull/2667)
* [OCPBUGS-85262](https://issues.redhat.com/browse/OCPBUGS-85262): Re-enable kubectl kuberc commands e2e tests [#2731](https://github.com/openshift/kubernetes/pull/2731)
* [OCPBUGS-92798](https://issues.redhat.com/browse/OCPBUGS-92798): Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) [#2717](https://github.com/openshift/kubernetes/pull/2717)
* [STOR-2961](https://issues.redhat.com/browse/STOR-2961): UPSTREAM: 138768: move VolumeGroupSnapshot to V1 [#2723](https://github.com/openshift/kubernetes/pull/2723)
* [CNTRLPLANE-3323](https://issues.redhat.com/browse/CNTRLPLANE-3323): Update openshift-hack/rebase.sh [#2701](https://github.com/openshift/kubernetes/pull/2701)
* [OCPBUGS-98100](https://issues.redhat.com/browse/OCPBUGS-98100): e2e: storage snapshot tests should read custom timeouts from manifest [#2719](https://github.com/openshift/kubernetes/pull/2719)
* [OCPBUGS-92836](https://issues.redhat.com/browse/OCPBUGS-92836): UPSTREAM: <carry>: upkeep cpu partitioning admission webhook [#2713](https://github.com/openshift/kubernetes/pull/2713)
* [STOR-2963](https://issues.redhat.com/browse/STOR-2963): Save SELinuxWarningController upgradeability to a ConfigMap [#2720](https://github.com/openshift/kubernetes/pull/2720)
* [OCPBUGS-90520](https://issues.redhat.com/browse/OCPBUGS-90520): UPSTREAM: 140211: Promote regression-issue-74839 to 1.5 [#2709](https://github.com/openshift/kubernetes/pull/2709)
* [OCPBUGS-99058](https://issues.redhat.com/browse/OCPBUGS-99058): Disable DRA extended resource test that requires dedicated DRA infrastructure [#2721](https://github.com/openshift/kubernetes/pull/2721)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2653](https://github.com/openshift/kubernetes/pull/2653)
* [Full changelog](https://github.com/openshift/kubernetes/compare/a466682e3867da746be24d7d56c6641612721d6c...c56d0ff2dbba9f3aa73e193deea591a74b298717)
### [hypershift](https://github.com/openshift/hypershift/tree/9ea2ca9357a719bccec22b4e222e52490aed545c)
* [CNTRLPLANE-3202](https://issues.redhat.com/browse/CNTRLPLANE-3202): add restore, OADP, and limitations docs for self-managed Azure DR [#9160](https://github.com/openshift/hypershift/pull/9160)
* [CNTRLPLANE-4038](https://issues.redhat.com/browse/CNTRLPLANE-4038): feat(supportedversion): bump latest supported OCP version to 5.1 [#9288](https://github.com/openshift/hypershift/pull/9288)
* [OCPBUGS-105865](https://issues.redhat.com/browse/OCPBUGS-105865): fix(nodepool): include only TLSSecurityProfile in config hash instead of full APIServer [#9287](https://github.com/openshift/hypershift/pull/9287)
* [AUTOSCALE-871](https://issues.redhat.com/browse/AUTOSCALE-871): add deployment path for standalone karpenter-operator [#9245](https://github.com/openshift/hypershift/pull/9245)
* [GCP-986](https://issues.redhat.com/browse/GCP-986): chore: add acwalczyk to gcp-reviewers alias [#9222](https://github.com/openshift/hypershift/pull/9222)
* NO-JIRA: Disable repo_gpgcheck for Microsoft repo in Dockerfile.e2e [#9290](https://github.com/openshift/hypershift/pull/9290)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): improve v2 test isolation [#9229](https://github.com/openshift/hypershift/pull/9229)
* NO-JIRA: feat(ci): split CI report into ARO HCP, KubeVirt, and Azure Self-Managed categories [#9282](https://github.com/openshift/hypershift/pull/9282)
* [OCPBUGS-101766](https://issues.redhat.com/browse/OCPBUGS-101766): enable TLSAdherence feature gate part on TechPreviewNoUpgrade [#9213](https://github.com/openshift/hypershift/pull/9213)
* [OCPBUGS-96908](https://issues.redhat.com/browse/OCPBUGS-96908): remove redhat-marketplace catalog from HyperShift [#8958](https://github.com/openshift/hypershift/pull/8958)
* [OCPBUGS-105555](https://issues.redhat.com/browse/OCPBUGS-105555): Update ubi-minimal base image to fix glib2 CVEs (CVE-2025-14087, CVE-2025-14512) [#9276](https://github.com/openshift/hypershift/pull/9276)
* [OCPBUGS-98065](https://issues.redhat.com/browse/OCPBUGS-98065): Prevent infraID and clusterID removal via parent-level CEL rules [#9102](https://github.com/openshift/hypershift/pull/9102)
* [OCPBUGS-105849](https://issues.redhat.com/browse/OCPBUGS-105849): Remove docs/compare tooling to fix Snyk security scan [#9285](https://github.com/openshift/hypershift/pull/9285)
* [CNTRLPLANE-3945](https://issues.redhat.com/browse/CNTRLPLANE-3945): fix(docs): set writable uv cache path for arc-runner-set [#9281](https://github.com/openshift/hypershift/pull/9281)
* [CNTRLPLANE-3945](https://issues.redhat.com/browse/CNTRLPLANE-3945): Migrate documentation tooling from mkdocs-material to zensical [#9139](https://github.com/openshift/hypershift/pull/9139)
* NO-JIRA: fix: separate gci-only pre-commit hooks from full lint-fix targets [#9272](https://github.com/openshift/hypershift/pull/9272)
* [CNTRLPLANE-3625](https://issues.redhat.com/browse/CNTRLPLANE-3625): Add aws-pod-identity-webhook e2e tls cases [#8953](https://github.com/openshift/hypershift/pull/8953)
* [OCPBUGS-105602](https://issues.redhat.com/browse/OCPBUGS-105602): fix broken relative reference [#9277](https://github.com/openshift/hypershift/pull/9277)
* [OCPBUGS-105597](https://issues.redhat.com/browse/OCPBUGS-105597): fix(ci): update GHA runner base image to unblock CI [#9275](https://github.com/openshift/hypershift/pull/9275)
* [OCPCLOUD-3261](https://issues.redhat.com/browse/OCPCLOUD-3261): feat(cloud providers): inject centralized TLS configuration [#8864](https://github.com/openshift/hypershift/pull/8864)
* [CNTRLPLANE-3959](https://issues.redhat.com/browse/CNTRLPLANE-3959): wire apiserver config through ignition server [#9136](https://github.com/openshift/hypershift/pull/9136)
* NO-JIRA: isolate NewSession tests from ambient AWS env vars [#8911](https://github.com/openshift/hypershift/pull/8911)
* [CNTRLPLANE-3984](https://issues.redhat.com/browse/CNTRLPLANE-3984): document all skills and commands in SKILLS.md [#9210](https://github.com/openshift/hypershift/pull/9210)
* [OCPBUGS-105193](https://issues.redhat.com/browse/OCPBUGS-105193): extract HCCO webhook validation into a dedicated controller [#9239](https://github.com/openshift/hypershift/pull/9239)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add manual trigger and fix path filter for docs publish [#9261](https://github.com/openshift/hypershift/pull/9261)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): correct wrangler pages deploy flags for docs publish [#9252](https://github.com/openshift/hypershift/pull/9252)
* [OCPBUGS-60093](https://issues.redhat.com/browse/OCPBUGS-60093): fix(upsert): add desired-state hash to detect spec field removals [#7713](https://github.com/openshift/hypershift/pull/7713)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add workflow to publish docs to Cloudflare Pages on merge [#9221](https://github.com/openshift/hypershift/pull/9221)
* [CNTRLPLANE-3291](https://issues.redhat.com/browse/CNTRLPLANE-3291): docs: add upstream documentation for configurable log levels [#9193](https://github.com/openshift/hypershift/pull/9193)
* [CNTRLPLANE-3978](https://issues.redhat.com/browse/CNTRLPLANE-3978): Fix CPO finalizer race leaving orphaned Azure Private Endpoint resources [#9194](https://github.com/openshift/hypershift/pull/9194)
* [CNTRLPLANE-3873](https://issues.redhat.com/browse/CNTRLPLANE-3873), [CNTRLPLANE-3874](https://issues.redhat.com/browse/CNTRLPLANE-3874), [OCPBUGS-94518](https://issues.redhat.com/browse/OCPBUGS-94518): update azure CPO overrides for 4.20, 4.21, 4.22 [#9211](https://github.com/openshift/hypershift/pull/9211)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): test(e2e): remove oc dependency in external oidc e2e tests [#9208](https://github.com/openshift/hypershift/pull/9208)
* [OCPBUGS-104543](https://issues.redhat.com/browse/OCPBUGS-104543): fix test isolation bug in EnsureDefaultSecurityGroupTagsTest [#9228](https://github.com/openshift/hypershift/pull/9228)
* NO-JIRA: build(deps): bump the github-dependencies group with 23 updates [#9190](https://github.com/openshift/hypershift/pull/9190)
* [OCPBUGS-104505](https://issues.redhat.com/browse/OCPBUGS-104505): fix(ci): trigger envtest workflows on dependency changes [#9215](https://github.com/openshift/hypershift/pull/9215)
* [CNTRLPLANE-3673](https://issues.redhat.com/browse/CNTRLPLANE-3673): add HO Konflux release gating documentation [#8947](https://github.com/openshift/hypershift/pull/8947)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): load plugin explicitly in bare mode for skill resolution [#9220](https://github.com/openshift/hypershift/pull/9220)
* [OCPBUGS-104528](https://issues.redhat.com/browse/OCPBUGS-104528): Update openshift API to resolve broken hypershift integration tests on K8s 1.30 [#9231](https://github.com/openshift/hypershift/pull/9231)
* [OCPBUGS-105207](https://issues.redhat.com/browse/OCPBUGS-105207): Revert "OCPBUGS-89689: (karpenter) use completed release image for unpinned NodeClaims during CP upgrade" [#9233](https://github.com/openshift/hypershift/pull/9233)
* NO-JIRA: fix(build): bump hack/tools Go version to 1.26.0 to match main module [#9223](https://github.com/openshift/hypershift/pull/9223)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): e2e: Remove osImageStream cleanup that violates immutability [#9206](https://github.com/openshift/hypershift/pull/9206)
* [OCPBUGS-100054](https://issues.redhat.com/browse/OCPBUGS-100054): Fix Azure Private clusters without external DNS [#9171](https://github.com/openshift/hypershift/pull/9171)
* [GCP-896](https://issues.redhat.com/browse/GCP-896): chore: add gbarabasz to gcp-reviewers alias [#9000](https://github.com/openshift/hypershift/pull/9000)
* [CNTRLPLANE-3979](https://issues.redhat.com/browse/CNTRLPLANE-3979): Add missing ProjectDevelopmentStream 4.14 [#9225](https://github.com/openshift/hypershift/pull/9225)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): emit lifecycle-aware JUnit for informing e2e tests [#9168](https://github.com/openshift/hypershift/pull/9168)
* NO-JIRA: add e2e-approvers owner alias, grant Dan Mace e2e role [#9216](https://github.com/openshift/hypershift/pull/9216)
* NO-JIRA: build(deps): bump the k8s-dependencies group across 1 directory with 12 updates [#9189](https://github.com/openshift/hypershift/pull/9189)
* [OCPBUGS-100184](https://issues.redhat.com/browse/OCPBUGS-100184): Wait for Azure ignition DNS before creating workers [#9172](https://github.com/openshift/hypershift/pull/9172)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): isolate Claude from push credentials in PR workflows [#9214](https://github.com/openshift/hypershift/pull/9214)
* [OCPBUGS-98983](https://issues.redhat.com/browse/OCPBUGS-98983): improve guest cluster state management reliability [#9198](https://github.com/openshift/hypershift/pull/9198)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#8954](https://github.com/openshift/hypershift/pull/8954)
* [OCPBUGS-100301](https://issues.redhat.com/browse/OCPBUGS-100301): fix(hostedcluster): handle Unknown status in ClusterVersionFailing inversion [#9186](https://github.com/openshift/hypershift/pull/9186)
* [OCPBUGS-89689](https://issues.redhat.com/browse/OCPBUGS-89689): (karpenter) use completed release image for unpinned NodeClaims during CP upgrade [#8957](https://github.com/openshift/hypershift/pull/8957)
* NO-JIRA: build(deps): bump the misc-dependencies group across 1 directory with 6 updates [#9164](https://github.com/openshift/hypershift/pull/9164)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): add e2e v2 test flow document [#9151](https://github.com/openshift/hypershift/pull/9151)
* docs: add July 2026 progress report blog post [#9057](https://github.com/openshift/hypershift/pull/9057)
* [OCPBUGS-100302](https://issues.redhat.com/browse/OCPBUGS-100302): fix(metrics): only report limited support when label โฆ [#9185](https://github.com/openshift/hypershift/pull/9185)
* NO-JIRA: build(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 [#9125](https://github.com/openshift/hypershift/pull/9125)
* [CNTRLPLANE-3943](https://issues.redhat.com/browse/CNTRLPLANE-3943): feat(destroy): add --force flag to strip finalizers on grace period expiry [#9134](https://github.com/openshift/hypershift/pull/9134)
* [STOR-2954](https://issues.redhat.com/browse/STOR-2954): inject centralized TLS configuration for storage operators [#8887](https://github.com/openshift/hypershift/pull/8887)
* Revert "CNTRLPLANE-3890: Add product-cli unit tests for HCP create cluster" [#9201](https://github.com/openshift/hypershift/pull/9201)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): resolve RHEL stream dynamically for boot images [#9099](https://github.com/openshift/hypershift/pull/9099)
* NO-JIRA: build(deps): bump the sigs-k8s-dependencies group across 1 directory with 8 updates [#9177](https://github.com/openshift/hypershift/pull/9177)
* [CNTRLPLANE-3890](https://issues.redhat.com/browse/CNTRLPLANE-3890): Add product-cli unit tests for HCP create cluster [#9107](https://github.com/openshift/hypershift/pull/9107)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): wire up AWS v2 e2e lifecycle test coverage [#9174](https://github.com/openshift/hypershift/pull/9174)
* [OCPBUGS-100140](https://issues.redhat.com/browse/OCPBUGS-100140): bracket IPv6 in OAuth issuer and callback URLs [#9120](https://github.com/openshift/hypershift/pull/9120)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): bump karpenter deps to 1.13.0 [#9170](https://github.com/openshift/hypershift/pull/9170)
* [CNTRLPLANE-3976](https://issues.redhat.com/browse/CNTRLPLANE-3976): Document management cluster vs hosted cluster feature gates [#9182](https://github.com/openshift/hypershift/pull/9182)
* [OCPBUGS-97804](https://issues.redhat.com/browse/OCPBUGS-97804): Avoid printing errors twice [#8931](https://github.com/openshift/hypershift/pull/8931)
* [CNTRLPLANE-3887](https://issues.redhat.com/browse/CNTRLPLANE-3887): test(e2e): add metricsSet filtering coverage to metrics forwarder test [#9078](https://github.com/openshift/hypershift/pull/9078)
* [OCPBUGS-86843](https://issues.redhat.com/browse/OCPBUGS-86843): fix(konnectivity): conditionally prefer IPv4 based on HCP network config [#9140](https://github.com/openshift/hypershift/pull/9140)
* [OCPBUGS-91511](https://issues.redhat.com/browse/OCPBUGS-91511): Fix CPO infinite requeue during deletion when OIDC provider is gone [#8894](https://github.com/openshift/hypershift/pull/8894)
* [OCPBUGS-98654](https://issues.redhat.com/browse/OCPBUGS-98654): delete_hosted_cluster.sh fails to run with no --dns-zone-rg-name flag [#8945](https://github.com/openshift/hypershift/pull/8945)
* NO-JIRA: docs: fix ARCHITECTURE.md to reflect current CPO image resolution [#9179](https://github.com/openshift/hypershift/pull/9179)
* [OCPBUGS-100087](https://issues.redhat.com/browse/OCPBUGS-100087): Replace exponential backoff with fixed-interval requeue in CRR controller [#9148](https://github.com/openshift/hypershift/pull/9148)
* [OCPBUGS-99783](https://issues.redhat.com/browse/OCPBUGS-99783): fix(e2e): check pre-upgrade HO version for shared role support [#8891](https://github.com/openshift/hypershift/pull/8891)
* [CNTRLPLANE-3709](https://issues.redhat.com/browse/CNTRLPLANE-3709): test(azure): enable Global Pull Secret test in Azure CI [#9073](https://github.com/openshift/hypershift/pull/9073)
* [CNTRLPLANE-3956](https://issues.redhat.com/browse/CNTRLPLANE-3956): Make EnsureGlobalPullSecret e2e test informing [#9167](https://github.com/openshift/hypershift/pull/9167)
* [CNTRLPLANE-2539](https://issues.redhat.com/browse/CNTRLPLANE-2539): Move generation of the CAPI Provider Role [#8305](https://github.com/openshift/hypershift/pull/8305)
* NO-JIRA: docs: add hash migration impact guidance and CPO data-plane component docs [#9161](https://github.com/openshift/hypershift/pull/9161)
* [CNTRLPLANE-3897](https://issues.redhat.com/browse/CNTRLPLANE-3897): Add product-cli unit tests for create nodepool [#9121](https://github.com/openshift/hypershift/pull/9121)
* [CNTRLPLANE-3600](https://issues.redhat.com/browse/CNTRLPLANE-3600): Bump k8s to v0.36.2, controller-runtime to v0.24.1, CAPI to v1.12.8 [#8695](https://github.com/openshift/hypershift/pull/8695)
* [CNTRLPLANE-3944](https://issues.redhat.com/browse/CNTRLPLANE-3944): Regenerate requirements.txt files with pinned --hash entries [#9135](https://github.com/openshift/hypershift/pull/9135)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): fix yq dependency for running upstream karpenter tests [#9060](https://github.com/openshift/hypershift/pull/9060)
* [OCPBUGS-99288](https://issues.redhat.com/browse/OCPBUGS-99288): Add proxy env vars to AWS cloud-controller-manager deployment [#9053](https://github.com/openshift/hypershift/pull/9053)
* [CNTRLPLANE-3604](https://issues.redhat.com/browse/CNTRLPLANE-3604): Add CAPI migration flag placeholder [#9145](https://github.com/openshift/hypershift/pull/9145)
* [CNTRLPLANE-3564](https://issues.redhat.com/browse/CNTRLPLANE-3564): test(awsprivatelink): add unit test for NoSuchHostedZone handling durโฆ [#9141](https://github.com/openshift/hypershift/pull/9141)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 [#9113](https://github.com/openshift/hypershift/pull/9113)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /hack/tools [#9111](https://github.com/openshift/hypershift/pull/9111)
* [CNTRLPLANE-3888](https://issues.redhat.com/browse/CNTRLPLANE-3888): docs: add on-demand jira-agent triggering and plugin install instructions [#9079](https://github.com/openshift/hypershift/pull/9079)
* [OCPBUGS-54776](https://issues.redhat.com/browse/OCPBUGS-54776): fix(ignition-server): log MCS output on HTTP request failures [#8936](https://github.com/openshift/hypershift/pull/8936)
* [CNTRLPLANE-400](https://issues.redhat.com/browse/CNTRLPLANE-400): feat(remediationAllowed in NP): propagate MHC RemediationAllowed to NodePool Ready condition [#9019](https://github.com/openshift/hypershift/pull/9019)
* NO-JIRA: align control-plane Dockerfile builder image with main Dockerfile [#9138](https://github.com/openshift/hypershift/pull/9138)
* [OCPBUGS-99768](https://issues.redhat.com/browse/OCPBUGS-99768): fix OSImageStream e2e test and Makefile test-changed for OCP 5.0 [#9115](https://github.com/openshift/hypershift/pull/9115)
* [CNTRLPLANE-3893](https://issues.redhat.com/browse/CNTRLPLANE-3893): Add product-cli unit tests for destroy cluster [#9116](https://github.com/openshift/hypershift/pull/9116)
* NO-JIRA: ci(deps): bump actions/checkout from 6.0.2 to 7.0.1 [#9090](https://github.com/openshift/hypershift/pull/9090)
* NO-JIRA: ci(deps): bump actions/setup-python from 6.2.0 to 7.0.0 [#9089](https://github.com/openshift/hypershift/pull/9089)
* NO-JIRA: ci(deps): bump actions/setup-go from 6.4.0 to 7.0.0 [#9029](https://github.com/openshift/hypershift/pull/9029)
* [OCPBUGS-86494](https://issues.redhat.com/browse/OCPBUGS-86494): fix(nodepool): preserve KubeVirt userdata Secrets during NodePool rollout [#8581](https://github.com/openshift/hypershift/pull/8581)
* [CNTRLPLANE-3910](https://issues.redhat.com/browse/CNTRLPLANE-3910): Fix e2e test reliability for mirroring tests and test-changed target [#9086](https://github.com/openshift/hypershift/pull/9086)
* [CNTRLPLANE-3919](https://issues.redhat.com/browse/CNTRLPLANE-3919): data race in TestEnqueueNodePoolsForCloudConfig [#9095](https://github.com/openshift/hypershift/pull/9095)
* NO-JIRA: chore(konflux): update Tekton task bundles to latest versions [#9081](https://github.com/openshift/hypershift/pull/9081)
* [NE-2815](https://issues.redhat.com/browse/NE-2815): feat: configure HAProxy version selection [#9040](https://github.com/openshift/hypershift/pull/9040)
* [CNTRLPLANE-3791](https://issues.redhat.com/browse/CNTRLPLANE-3791): fix: revert api-lint --whole-files to avoid surfacing pre-existing violations [#9071](https://github.com/openshift/hypershift/pull/9071)
* [OCPBUGS-99014](https://issues.redhat.com/browse/OCPBUGS-99014): Authenticate Konnectivity agents with cluster CA [#9031](https://github.com/openshift/hypershift/pull/9031)
* [CNTRLPLANE-3032](https://issues.redhat.com/browse/CNTRLPLANE-3032): test: add e2e v2 tests for NodePool OSImageStream [#9033](https://github.com/openshift/hypershift/pull/9033)
* [OCPBUGS-98744](https://issues.redhat.com/browse/OCPBUGS-98744): compare post-upgrade RHCOS version against pre-upgrade instead of release metadata [#9014](https://github.com/openshift/hypershift/pull/9014)
* [OCPBUGS-98462](https://issues.redhat.com/browse/OCPBUGS-98462): add jitter to AWS endpoint service requeue delay [#8996](https://github.com/openshift/hypershift/pull/8996)
* [OCPBUGS-98465](https://issues.redhat.com/browse/OCPBUGS-98465): prevent DS crash in pull secret verifier and add propagation diagnostics [#8991](https://github.com/openshift/hypershift/pull/8991)
* [OCPBUGS-99289](https://issues.redhat.com/browse/OCPBUGS-99289): Exclude aggregated docs page from search index [#9043](https://github.com/openshift/hypershift/pull/9043)
* [CNTRLPLANE-3199](https://issues.redhat.com/browse/CNTRLPLANE-3199): add etcd backup infrastructure and docs for self-managed Azure [#8785](https://github.com/openshift/hypershift/pull/8785)
* [CNTRLPLANE-3862](https://issues.redhat.com/browse/CNTRLPLANE-3862): fix(ci): reintroduce verify-ci make target for GHA verify workflow [#9045](https://github.com/openshift/hypershift/pull/9045)
* [CNTRLPLANE-3859](https://issues.redhat.com/browse/CNTRLPLANE-3859): Restructure pre-commit push hooks for faster local feedback [#9042](https://github.com/openshift/hypershift/pull/9042)
* [CNTRLPLANE-3434](https://issues.redhat.com/browse/CNTRLPLANE-3434): add ho-release-gate pipeline for nightly promotion [#8602](https://github.com/openshift/hypershift/pull/8602)
* NO-JIRA: fix(cpo): regenerate stale ModernTLS test fixtures [#9041](https://github.com/openshift/hypershift/pull/9041)
* [CNTRLPLANE-647](https://issues.redhat.com/browse/CNTRLPLANE-647): Expose v4/v6InternalSubnet OVN-Kubernetes configuration in HostedCluster API [#8249](https://github.com/openshift/hypershift/pull/8249)
* [ARO-27360](https://issues.redhat.com/browse/ARO-27360): Add ACR pull identity configured metric [#8840](https://github.com/openshift/hypershift/pull/8840)
* [ARO-24037](https://issues.redhat.com/browse/ARO-24037): gate cloud config on hash to prevent serving stale content [#8946](https://github.com/openshift/hypershift/pull/8946)
* [CNTRLPLANE-3615](https://issues.redhat.com/browse/CNTRLPLANE-3615): add tls security profile configuration for the etcd [#8871](https://github.com/openshift/hypershift/pull/8871)
* [OCPBUGS-88312](https://issues.redhat.com/browse/OCPBUGS-88312): use in-cluster service for oauth-server [#8772](https://github.com/openshift/hypershift/pull/8772)
* [CNTRLPLANE-3791](https://issues.redhat.com/browse/CNTRLPLANE-3791): make pre-commit hooks resilient to mock generation failures [#9016](https://github.com/openshift/hypershift/pull/9016)
* NO-JIRA: update Tekton task bundles to latest versions [#9038](https://github.com/openshift/hypershift/pull/9038)
* [OCPBUGS-98384](https://issues.redhat.com/browse/OCPBUGS-98384): fix bastion cleanup KeyPair leak by capturing infraID/region eagerly [#8982](https://github.com/openshift/hypershift/pull/8982)
* [CNTRLPLANE-3674](https://issues.redhat.com/browse/CNTRLPLANE-3674): Add Jira Agent onboarding guide [#8814](https://github.com/openshift/hypershift/pull/8814)
* [CNTRLPLANE-3825](https://issues.redhat.com/browse/CNTRLPLANE-3825): move test conventions to TESTING.md [#9036](https://github.com/openshift/hypershift/pull/9036)
* [OCPSTRAT-3150](https://issues.redhat.com/browse/OCPSTRAT-3150): Add etcd sharding by resource kind support [#8705](https://github.com/openshift/hypershift/pull/8705)
* [OCPBUGS-98695](https://issues.redhat.com/browse/OCPBUGS-98695): add Azure CPO overrides for 4.22 [#9010](https://github.com/openshift/hypershift/pull/9010)
* NO-JIRA: ci(deps): bump actions/setup-node from 6.4.0 to 7.0.0 [#9030](https://github.com/openshift/hypershift/pull/9030)
* [CNTRLPLANE-3763](https://issues.redhat.com/browse/CNTRLPLANE-3763): tag bastion resources with e2e provenance [#9022](https://github.com/openshift/hypershift/pull/9022)
* [OCPBUGS-98575](https://issues.redhat.com/browse/OCPBUGS-98575): feat: inject hosted cluster TLS security profile into packageserver [#9001](https://github.com/openshift/hypershift/pull/9001)
* [AUTOSCALE-870](https://issues.redhat.com/browse/AUTOSCALE-870): add KarpenterOperator tech-preview FeatureGate [#8976](https://github.com/openshift/hypershift/pull/8976)
* [CNTRLPLANE-3774](https://issues.redhat.com/browse/CNTRLPLANE-3774): fix: control-plane-operator: improve opaque conditions [#8804](https://github.com/openshift/hypershift/pull/8804)
* [CNTRLPLANE-3695](https://issues.redhat.com/browse/CNTRLPLANE-3695): refactor(hcco): extract machine-config-daemon pod name format to constant [#8988](https://github.com/openshift/hypershift/pull/8988)
* [CNTRLPLANE-3820](https://issues.redhat.com/browse/CNTRLPLANE-3820): add cleanleaked tool for AWS leaked resource cleanup [#8964](https://github.com/openshift/hypershift/pull/8964)
* [SPLAT-2743](https://issues.redhat.com/browse/SPLAT-2743): aws/ccm - remove inline iam policy patch [#8835](https://github.com/openshift/hypershift/pull/8835)
* NO-JIRA: Add validateOnUpdateTableInput to envtest and fix test specs [#9015](https://github.com/openshift/hypershift/pull/9015)
* [OCPBUGS-98461](https://issues.redhat.com/browse/OCPBUGS-98461): requeue CRR on transiently unavailable resources [#8997](https://github.com/openshift/hypershift/pull/8997)
* [OCPBUGS-98718](https://issues.redhat.com/browse/OCPBUGS-98718): retry CreateVpcEndpoint on AWS throttle errors [#9012](https://github.com/openshift/hypershift/pull/9012)
* [CNTRLPLANE-3030](https://issues.redhat.com/browse/CNTRLPLANE-3030): feat(nodepool,ignition-server): consume os-stream and add ValidOSImageStream condition [#8792](https://github.com/openshift/hypershift/pull/8792)
* [OCPBUGS-88738](https://issues.redhat.com/browse/OCPBUGS-88738): clean up orphaned mirrored ConfigMaps on NodePool deletion [#8890](https://github.com/openshift/hypershift/pull/8890)
* [OCPBUGS-97830](https://issues.redhat.com/browse/OCPBUGS-97830): Add wait-for-etcd init container to oauth-apiserver [#8940](https://github.com/openshift/hypershift/pull/8940)
* fix(ci): make race detection opt-out for pre-push hook [#9003](https://github.com/openshift/hypershift/pull/9003)
* [CNTRLPLANE-3763](https://issues.redhat.com/browse/CNTRLPLANE-3763): tag CLI and e2e AWS resources with infra-id, cluster-name, and source [#8909](https://github.com/openshift/hypershift/pull/8909)
* [OCPBUGS-93462](https://issues.redhat.com/browse/OCPBUGS-93462): Fix stale resourceVersion in HCCO patchHCPStatusCondition [#8902](https://github.com/openshift/hypershift/pull/8902)
* [OCPBUGS-98466](https://issues.redhat.com/browse/OCPBUGS-98466): retry Prometheus query exec on transient konnectivity 502 [#8995](https://github.com/openshift/hypershift/pull/8995)
* [OCPBUGS-98464](https://issues.redhat.com/browse/OCPBUGS-98464): handle stale DaemonSet in GlobalPullSecret test [#8990](https://github.com/openshift/hypershift/pull/8990)
* [SPLAT-2741](https://issues.redhat.com/browse/SPLAT-2741): Add SetSecurityGroups perms for AWS CCM for BYO SG on AWS NLB [#8401](https://github.com/openshift/hypershift/pull/8401)
* [OCPBUGS-98571](https://issues.redhat.com/browse/OCPBUGS-98571): Skip Azure topology LB scope override for ARO HCP IngressController [#8992](https://github.com/openshift/hypershift/pull/8992)
* [CNTRLPLANE-3553](https://issues.redhat.com/browse/CNTRLPLANE-3553): Wire usesRunc detection into RHEL stream resolution [#8832](https://github.com/openshift/hypershift/pull/8832)
* [OCPBUGS-88531](https://issues.redhat.com/browse/OCPBUGS-88531): Remove CPO-side restart logic for CNO operands [#8751](https://github.com/openshift/hypershift/pull/8751)
* [CNTRLPLANE-3831](https://issues.redhat.com/browse/CNTRLPLANE-3831): skip UpstreamParity OIDC tests on releases before 4.23 [#8987](https://github.com/openshift/hypershift/pull/8987)
* [OCPBUGS-98086](https://issues.redhat.com/browse/OCPBUGS-98086): fix(cpo,hcco): prevent premature KAS convergence during KMS key rotation [#8970](https://github.com/openshift/hypershift/pull/8970)
* [OCPBUGS-78310](https://issues.redhat.com/browse/OCPBUGS-78310): fix(cli): initialize controller-runtime logger in product-cli [#8955](https://github.com/openshift/hypershift/pull/8955)
* [OCPBUGS-63720](https://issues.redhat.com/browse/OCPBUGS-63720): orphan machines when managed identity is invalid on clusโฆ [#8296](https://github.com/openshift/hypershift/pull/8296)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/hypershift/compare/8ea96d7f8cfa3eb4e7dc93be96a04341fc5a2240...9ea2ca9357a719bccec22b4e222e52490aed545c)
### [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm/tree/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f)
* [OCPCLOUD-3593](https://issues.redhat.com/browse/OCPCLOUD-3593): Rebase from upstream IBM-Cloud/cloud-provider-ibm release-1.36 (K8s 1.36.2) [#109](https://github.com/openshift/cloud-provider-ibm/pull/109)
* [Full changelog](https://github.com/openshift/cloud-provider-ibm/compare/ef8fcc288d9248cd149f181e7f5c896f4a10eb3b...11bc35dd6fd5163259023a6f1dfcc59ce813ab5f)
### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/3a89d7d17d25727270414b07d3daaa3bc329d743)
* NO-JIRA: standardize build paths [#155](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/155)
* [STOR-2921](https://issues.redhat.com/browse/STOR-2921): Rebase to v5.2.27 for OCP 5.0 [#154](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/154)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/f78abbb3502a875b7ddf769cf6b7c1b8e3ebba29...3a89d7d17d25727270414b07d3daaa3bc329d743)
### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/be4fd01725ce5ab0b47f846c905a349aeee8ab53)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#176](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/176)
* [STOR-2921](https://issues.redhat.com/browse/STOR-2921): update deployment manifests from upstream [#174](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/174)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/e6d299f720a76dd25fcdc304d408f43c33a42fb6...be4fd01725ce5ab0b47f846c905a349aeee8ab53)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/286dd2de7957e9c2897e152417f16907d324d819)
* ๐ OCPCLOUD-3602: Merge https://github.com/kubernetes-sigs/cluster-api-provider-ibmcloud:v0.14.0 (5d081d1) into main [#161](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/161)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#164](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/164)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/0fdc00b1c1f411da3c385e27e63d909761ad1aa9...286dd2de7957e9c2897e152417f16907d324d819)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/2615d13b730255b21ccb401d3dc039006c54a4fe)
* [OCPCLOUD-3618](https://issues.redhat.com/browse/OCPCLOUD-3618): Bump k8s 1.36 [#100](https://github.com/openshift/machine-api-provider-ibmcloud/pull/100)
* [OCPBUGS-96827](https://issues.redhat.com/browse/OCPBUGS-96827): bump golang.org/x/net to v0.57.0 [#98](https://github.com/openshift/machine-api-provider-ibmcloud/pull/98)
* [OCPCLOUD-3641](https://issues.redhat.com/browse/OCPCLOUD-3641): Support configurable boot volume profile, size, IOPS and bandwidth [#97](https://github.com/openshift/machine-api-provider-ibmcloud/pull/97)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/80a91b3fb96a4fb74ed03e895d617b462ad21db2...2615d13b730255b21ccb401d3dc039006c54a4fe)
### [insights-operator](https://github.com/openshift/insights-operator/tree/8494b69b8075fd1e8eac49db77bcda7588078155)
* [CCXDEV-16647](https://issues.redhat.com/browse/CCXDEV-16647): add create gatherer skill [#1335](https://github.com/openshift/insights-operator/pull/1335)
* NO-JIRA: remove katarina [#1336](https://github.com/openshift/insights-operator/pull/1336)
* [CCXDEV-16629](https://issues.redhat.com/browse/CCXDEV-16629): Add network policy [#1331](https://github.com/openshift/insights-operator/pull/1331)
* [CCXDEV-15210](https://issues.redhat.com/browse/CCXDEV-15210): secrets and configmap revisions count gathering [#1316](https://github.com/openshift/insights-operator/pull/1316)
* [OCPBUGS-98690](https://issues.redhat.com/browse/OCPBUGS-98690): Fix indentation bug on livenessProbe [#1320](https://github.com/openshift/insights-operator/pull/1320)
* [OCPBUGS-96894](https://issues.redhat.com/browse/OCPBUGS-96894): Update net and crypto libraries [#1321](https://github.com/openshift/insights-operator/pull/1321)
* [CCXDEV-16524](https://issues.redhat.com/browse/CCXDEV-16524): gather alertmanager configuration [#1322](https://github.com/openshift/insights-operator/pull/1322)
* NO-JIRA: Update misleading docs on the QEMU gatherer [#1319](https://github.com/openshift/insights-operator/pull/1319)
* [Full changelog](https://github.com/openshift/insights-operator/compare/ad672d905ed6c2df22de2d2ccf6712e04abf10f9...8494b69b8075fd1e8eac49db77bcda7588078155)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/7c9aa14915e639edd20bc0869747487e2e73fe51)
* [CCXDEV-16674](https://issues.redhat.com/browse/CCXDEV-16674): chore: add clippy linting [#87](https://github.com/openshift/insights-runtime-extractor/pull/87)
* NO-JIRA: Add new owners required for managing OCP CI config [#86](https://github.com/openshift/insights-runtime-extractor/pull/86)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/ce30b4f9bc3ec867b976886a5207d36c50a396d9...7c9aa14915e639edd20bc0869747487e2e73fe51)
### [ironic](https://github.com/openshift/ironic-image/tree/cd71206741658e6cef620fd5545a6bfce5f6ab78)
* [OKD-421](https://issues.redhat.com/browse/OKD-421): Fix Dockerfile.scos crypto-policies PQ failure on CentOS Stream 10 [#886](https://github.com/openshift/ironic-image/pull/886)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#873](https://github.com/openshift/ironic-image/pull/873)
* NO-ISSUE: Merge upstream 2026 07 24 [#872](https://github.com/openshift/ironic-image/pull/872)
* NO-ISSUE: Filter blank lines from build-packages-list.ocp in Dockerfile [#869](https://github.com/openshift/ironic-image/pull/869)
* [METAL-1912](https://issues.redhat.com/browse/METAL-1912): Add PQC support until we have pqc minimal images available [#871](https://github.com/openshift/ironic-image/pull/871)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#867](https://github.com/openshift/ironic-image/pull/867)
* [METAL-1898](https://issues.redhat.com/browse/METAL-1898): Add ironic-prometheus-exporter to update-requirements workflow [#866](https://github.com/openshift/ironic-image/pull/866)
* [Full changelog](https://github.com/openshift/ironic-image/compare/3320724e7b08113b20b518af155fb44aabc87093...cd71206741658e6cef620fd5545a6bfce5f6ab78)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/75280df7399ca69beae5a5b2793b7a9697175a2f)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#299](https://github.com/openshift/ironic-agent-image/pull/299)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#297](https://github.com/openshift/ironic-agent-image/pull/297)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#295](https://github.com/openshift/ironic-agent-image/pull/295)
* NO-ISSUE: Filter blank lines from build-packages-list.ocp in Dockerfile [#292](https://github.com/openshift/ironic-agent-image/pull/292)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#293](https://github.com/openshift/ironic-agent-image/pull/293)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#291](https://github.com/openshift/ironic-agent-image/pull/291)
* [METAL-1878](https://issues.redhat.com/browse/METAL-1878): [s2i] Move direct dependencies from packages to source [#290](https://github.com/openshift/ironic-agent-image/pull/290)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/5d658b9a168b136153842afbce46ab0e874f404d...75280df7399ca69beae5a5b2793b7a9697175a2f)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/629d3d9eda8e9fee1e0d779c0ed9a3632326baef)
* no-jira: rename guest kubeconfig back to target kubeconfig [#21](https://github.com/openshift/karpenter-operator/pull/21)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Add make target and scripts for karpenter core regression e2e tests [#20](https://github.com/openshift/karpenter-operator/pull/20)
* [AUTOSCALE-871](https://issues.redhat.com/browse/AUTOSCALE-871): allow Karpenter Operator to run in ManagementCluster mode [#19](https://github.com/openshift/karpenter-operator/pull/19)
* no-jira: change karpenter CR singleton name to default [#17](https://github.com/openshift/karpenter-operator/pull/17)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): Release chores 5.0 for Karpenter [#18](https://github.com/openshift/karpenter-operator/pull/18)
* [AUTOSCALE-806](https://issues.redhat.com/browse/AUTOSCALE-806): Introduce Karpenter API lifecycle object and controller [#16](https://github.com/openshift/karpenter-operator/pull/16)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/7a35066ed99bdab16a8ddb2f82260144621630cc...629d3d9eda8e9fee1e0d779c0ed9a3632326baef)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/13118bff15103b31a6528bf8de2d0d6de05f4742)
* [OCPBUGS-99649](https://issues.redhat.com/browse/OCPBUGS-99649): Reinstall tzdata if /usr/share/zoneinfo is missing [#246](https://github.com/openshift/images/pull/246)
* [NE-2223](https://issues.redhat.com/browse/NE-2223): Bump HAProxy to 3.2 in egress DNS proxy [#244](https://github.com/openshift/images/pull/244)
* [NE-2716](https://issues.redhat.com/browse/NE-2716): Replace iptables with nftables in origin-egress-router [#242](https://github.com/openshift/images/pull/242)
* [Full changelog](https://github.com/openshift/images/compare/c0471a7e1f4d7ca01b7089ee2993ca659cd84594...13118bff15103b31a6528bf8de2d0d6de05f4742)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
* [OCPBUGS-93753](https://issues.redhat.com/browse/OCPBUGS-93753): Bump openshift/kubernetes-metrics-server to v0.9.0 [#71](https://github.com/openshift/kubernetes-metrics-server/pull/71)
* [OCPBUGS-87412](https://issues.redhat.com/browse/OCPBUGS-87412): Updating ose-kube-metrics-server-container image to be consistent with ART for 5.0 [#69](https://github.com/openshift/kubernetes-metrics-server/pull/69)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/f4cd53392e69c6ba7c2d878ad929f6cdfb131b1d...3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/019ecc7d533333dfd3bf8893e78cd7ec6e282f01)
* [OCPBUGS-99282](https://issues.redhat.com/browse/OCPBUGS-99282): embed a copy of the timezone database [#148](https://github.com/openshift/kube-state-metrics/pull/148)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/b5df90392fbb08eb4c48e8a07f35b34a4c846312...019ecc7d533333dfd3bf8893e78cd7ec6e282f01)
### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/5eb884abcd2ff17ae8d7b2691ca12494597c08a6)
* [OCPBUGS-87345](https://issues.redhat.com/browse/OCPBUGS-87345): Updating ose-kubevirt-cloud-controller-manager-container image to be consistent with ART for 5.0 [#75](https://github.com/openshift/cloud-provider-kubevirt/pull/75)
* [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/76dd5a6fa9e86573bf3dfb79be17edf832e3bae1...5eb884abcd2ff17ae8d7b2691ca12494597c08a6)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/0db39ee372bf7b75f56898fd2df555e063d32952)
* [OCPBUGS-85110](https://issues.redhat.com/browse/OCPBUGS-85110): Move required-scc annotation to pod template for machine-api-controllers [#1511](https://github.com/openshift/machine-api-operator/pull/1511)
* [OCPBUGS-100056](https://issues.redhat.com/browse/OCPBUGS-100056): fix: skip Multisubnet test for single network infra [#1527](https://github.com/openshift/machine-api-operator/pull/1527)
* [OCPBUGS-99903](https://issues.redhat.com/browse/OCPBUGS-99903): Fixing test issue where error result was for other resource type [#1524](https://github.com/openshift/machine-api-operator/pull/1524)
* [OCPBUGS-100067](https://issues.redhat.com/browse/OCPBUGS-100067): Deduplicate unchanged status upgrade events [#1526](https://github.com/openshift/machine-api-operator/pull/1526)
* [CORS-4521](https://issues.redhat.com/browse/CORS-4521): GCP: Add regional permission [#1523](https://github.com/openshift/machine-api-operator/pull/1523)
* [OCPCLOUD-3614](https://issues.redhat.com/browse/OCPCLOUD-3614): bump k8s and openshift deps [#1520](https://github.com/openshift/machine-api-operator/pull/1520)
* [SPLAT-2854](https://issues.redhat.com/browse/SPLAT-2854): Fixing issue related to unintended VAP interactions [#1518](https://github.com/openshift/machine-api-operator/pull/1518)
* [SPLAT-2858](https://issues.redhat.com/browse/SPLAT-2858): Fixing test issue where error result was for other resource type [#1522](https://github.com/openshift/machine-api-operator/pull/1522)
* [SPLAT-2813](https://issues.redhat.com/browse/SPLAT-2813): Create VAP E2Es [#1517](https://github.com/openshift/machine-api-operator/pull/1517)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/c0b2d2c9c112bc46d8b4ac1c92e7fd0f216ad826...0db39ee372bf7b75f56898fd2df555e063d32952)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/0df05f6ea615ec212f68633f92d01f6e248d2a34)
* [OCPBUGS-105426](https://issues.redhat.com/browse/OCPBUGS-105426): OCPBUGS-105430: OCPBUGS-105431: OCPBUGS-105315: Fix duplicate template error and e2es [#6387](https://github.com/openshift/machine-config-operator/pull/6387)
* [OCPBUGS-59197](https://issues.redhat.com/browse/OCPBUGS-59197): Fix MOSB image deletion race during MOSC removal [#6348](https://github.com/openshift/machine-config-operator/pull/6348)
* [OCPBUGS-83562](https://issues.redhat.com/browse/OCPBUGS-83562): Bump kubensmnt dependency and service to v1.3.0 [#6051](https://github.com/openshift/machine-config-operator/pull/6051)
* NO-ISSUE: Add fix TC 63866 failing in CI job [#6380](https://github.com/openshift/machine-config-operator/pull/6380)
* [MCO-2256](https://issues.redhat.com/browse/MCO-2256): Drop RHEL8 support [#6130](https://github.com/openshift/machine-config-operator/pull/6130)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): update dependencies to the latest after several Feature promotions to default [#6393](https://github.com/openshift/machine-config-operator/pull/6393)
* [OKD-419](https://issues.redhat.com/browse/OKD-419): Add missing variant check for SCOS [#6371](https://github.com/openshift/machine-config-operator/pull/6371)
* [OCPBUGS-105432](https://issues.redhat.com/browse/OCPBUGS-105432): fix nil pointer panic in IRI controller informer race [#6385](https://github.com/openshift/machine-config-operator/pull/6385)
* NO-ISSUE: Adapt vsphere bootimage tests for mult-vcenter scenarios [#6317](https://github.com/openshift/machine-config-operator/pull/6317)
* [OCPBUGS-92062](https://issues.redhat.com/browse/OCPBUGS-92062): reduce memory usage in MCC and MCD [#6259](https://github.com/openshift/machine-config-operator/pull/6259)
* [OCPBUGS-100433](https://issues.redhat.com/browse/OCPBUGS-100433): Update AMI Whitelist [#6358](https://github.com/openshift/machine-config-operator/pull/6358)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part2 Migrate MCO OCB [#6340](https://github.com/openshift/machine-config-operator/pull/6340)
* [MCO-1814](https://issues.redhat.com/browse/MCO-1814), [MCO-2377](https://issues.redhat.com/browse/MCO-2377): Setup metrics for builds, Add metric to gather how many people are using OCL [#6316](https://github.com/openshift/machine-config-operator/pull/6316)
* [OCPNODE-4040](https://issues.redhat.com/browse/OCPNODE-4040): Use single KubeletConfigAccepted condition type with True/False status [#5854](https://github.com/openshift/machine-config-operator/pull/5854)
* [OCPBUGS-92182](https://issues.redhat.com/browse/OCPBUGS-92182): OCPBUGS-99219: Use providerSpec.Template in vSphere machineset reconciliation [#6234](https://github.com/openshift/machine-config-operator/pull/6234)
* [OCPBUGS-99696](https://issues.redhat.com/browse/OCPBUGS-99696): Add extension verification failure test cases OCP-89090 and OCP-89095 [#6333](https://github.com/openshift/machine-config-operator/pull/6333)
* [MCO-2485](https://issues.redhat.com/browse/MCO-2485): Mark scale-up test as 'informing' [#6364](https://github.com/openshift/machine-config-operator/pull/6364)
* [OCPBUGS-100458](https://issues.redhat.com/browse/OCPBUGS-100458): Adapt bootimage tests for CAPI migration [#6363](https://github.com/openshift/machine-config-operator/pull/6363)
* [MCO-1540](https://issues.redhat.com/browse/MCO-1540): Set up events for builds [#6252](https://github.com/openshift/machine-config-operator/pull/6252)
* [MCO-2482](https://issues.redhat.com/browse/MCO-2482): Revert "MCO-2470: Disable scale-up test support for AWS and vSphere" [#6356](https://github.com/openshift/machine-config-operator/pull/6356)
* [TRT-2875](https://issues.redhat.com/browse/TRT-2875): Revert #6303 "MCO-2205: Make ImageModeStatusReporting MCP count test more resilient on SNO" [#6359](https://github.com/openshift/machine-config-operator/pull/6359)
* [MCO-2205](https://issues.redhat.com/browse/MCO-2205): Make ImageModeStatusReporting MCP count test more resilient on SNO [#6303](https://github.com/openshift/machine-config-operator/pull/6303)
* [OCPBUGS-98316](https://issues.redhat.com/browse/OCPBUGS-98316): Fix SHA idempotency test in nmstate-configuration.sh [#6291](https://github.com/openshift/machine-config-operator/pull/6291)
* [OCPBUGS-100389](https://issues.redhat.com/browse/OCPBUGS-100389): machine-config-daemon-firstboot: disable ostree fsync during bootstrap [#6122](https://github.com/openshift/machine-config-operator/pull/6122)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part 1 Migrate OCB test cases from openshift-tests-private [#6080](https://github.com/openshift/machine-config-operator/pull/6080)
* NO-ISSUE: test MCC proxy. Refactor TC 52373 proxy test. [#6355](https://github.com/openshift/machine-config-operator/pull/6355)
* [MCO-2468](https://issues.redhat.com/browse/MCO-2468): Cache backed OSImageStreams for PIS [#6329](https://github.com/openshift/machine-config-operator/pull/6329)
* NO-ISSUE: Fix setArchitectureAndCheckStatus corrupting multi-label annotations [#6347](https://github.com/openshift/machine-config-operator/pull/6347)
* [OCPBUGS-100277](https://issues.redhat.com/browse/OCPBUGS-100277): Fix TC 43278 failing when release payload has no MCO commit info [#6349](https://github.com/openshift/machine-config-operator/pull/6349)
* NO-ISSUE: Fix incorrect OSImageStreams log [#6338](https://github.com/openshift/machine-config-operator/pull/6338)
* [MCO-2244](https://issues.redhat.com/browse/MCO-2244): Update MCO dependencies to Kubernetes 1.36 [#6321](https://github.com/openshift/machine-config-operator/pull/6321)
* [MCO-2470](https://issues.redhat.com/browse/MCO-2470): Disable scale-up test support for AWS and vSphere [#6344](https://github.com/openshift/machine-config-operator/pull/6344)
* NO-ISSUE: fix fencing_validator ocdebug fence dispatch race condition [#6341](https://github.com/openshift/machine-config-operator/pull/6341)
* [OCPBUGS-82139](https://issues.redhat.com/browse/OCPBUGS-82139): Add control-plane NoSchedule taint support alongside master taint [#6313](https://github.com/openshift/machine-config-operator/pull/6313)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#6334](https://github.com/openshift/machine-config-operator/pull/6334)
* NO-ISSUE: Use context instead of discrete signal [#6337](https://github.com/openshift/machine-config-operator/pull/6337)
* [OCPNODE-4518](https://issues.redhat.com/browse/OCPNODE-4518): Block runc on RHEL 10 via OSImageURL stream class inspection [#6238](https://github.com/openshift/machine-config-operator/pull/6238)
* [MCO-2380](https://issues.redhat.com/browse/MCO-2380): MCO-2381: Expose MachineOSBuild Status Conditions on Paused MachineConfigPools and add E2E Tests for Paused Pool Builds [#6282](https://github.com/openshift/machine-config-operator/pull/6282)
* [MCO-2414](https://issues.redhat.com/browse/MCO-2414): Add unit tests for osImageStream [#6312](https://github.com/openshift/machine-config-operator/pull/6312)
* NO-ISSUE: extended tests, restore initial maxUnavailable when modified [#6336](https://github.com/openshift/machine-config-operator/pull/6336)
* [OCPBUGS-99695](https://issues.redhat.com/browse/OCPBUGS-99695): Add TC 88940- Apply password only if changes exist [#6328](https://github.com/openshift/machine-config-operator/pull/6328)
* NO-ISSUE: add AWS marketplace polarion ID test [#6330](https://github.com/openshift/machine-config-operator/pull/6330)
* [MCO-2184](https://issues.redhat.com/browse/MCO-2184): Adapt scale extended tests to support osstreams [#6299](https://github.com/openshift/machine-config-operator/pull/6299)
* [CNTRLPLANE-3840](https://issues.redhat.com/browse/CNTRLPLANE-3840): Remove ExternalTopologyMode guard from OSImageStream bootstrap [#6308](https://github.com/openshift/machine-config-operator/pull/6308)
* [MCO-2450](https://issues.redhat.com/browse/MCO-2450): Enable OS ImageStreams in OKD [#6314](https://github.com/openshift/machine-config-operator/pull/6314)
* [MCO-1333](https://issues.redhat.com/browse/MCO-1333): Validate OCL Containerfiles [#6187](https://github.com/openshift/machine-config-operator/pull/6187)
* NO-ISSUE: Add reusable utilities for image inspection [#6327](https://github.com/openshift/machine-config-operator/pull/6327)
* [MCO-1944](https://issues.redhat.com/browse/MCO-1944): Add NetworkPolicy Test case [#6283](https://github.com/openshift/machine-config-operator/pull/6283)
* [MCO-2413](https://issues.redhat.com/browse/MCO-2413): Image inspection cache [#6306](https://github.com/openshift/machine-config-operator/pull/6306)
* [MCO-1847](https://issues.redhat.com/browse/MCO-1847): adapt tc 52373 to new AWS marketplace feature [#6324](https://github.com/openshift/machine-config-operator/pull/6324)
* [MCO-1847](https://issues.redhat.com/browse/MCO-1847): update AWS backdated images in extended tests [#6320](https://github.com/openshift/machine-config-operator/pull/6320)
* [CORENET-5972](https://issues.redhat.com/browse/CORENET-5972): Add openvswitch-ipsec package into ipsec plugin [#4878](https://github.com/openshift/machine-config-operator/pull/4878)
* [MCO-2408](https://issues.redhat.com/browse/MCO-2408): Improve/Reduce code/duplicated logic in OsImageBuilderInNode [#6270](https://github.com/openshift/machine-config-operator/pull/6270)
* [MCO-2424](https://issues.redhat.com/browse/MCO-2424): Fix cert rotation timeout [#6309](https://github.com/openshift/machine-config-operator/pull/6309)
* [MCO-1990](https://issues.redhat.com/browse/MCO-1990): Irreconcilable configs test suite [#6085](https://github.com/openshift/machine-config-operator/pull/6085)
* [OCPBUGS-98745](https://issues.redhat.com/browse/OCPBUGS-98745): MCO-2424: add missing RBAC for pkis resource in MCC ClusterRole [#6307](https://github.com/openshift/machine-config-operator/pull/6307)
* [MCO-2301](https://issues.redhat.com/browse/MCO-2301): AWS Marketplace bootimage update support [#6015](https://github.com/openshift/machine-config-operator/pull/6015)
* [MCO-2407](https://issues.redhat.com/browse/MCO-2407): Move OSImageStream sync to MCC [#6278](https://github.com/openshift/machine-config-operator/pull/6278)
* [MCO-2427](https://issues.redhat.com/browse/MCO-2427): move password, bootimages and cpms suites to longduration suite [#6302](https://github.com/openshift/machine-config-operator/pull/6302)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): upgrade CRIOCredentialProviderConfig to v1 [#6220](https://github.com/openshift/machine-config-operator/pull/6220)
* [OCPBUGS-98210](https://issues.redhat.com/browse/OCPBUGS-98210): Fix imagestream detection with extra guard [#6296](https://github.com/openshift/machine-config-operator/pull/6296)
* [MCO-1997](https://issues.redhat.com/browse/MCO-1997): MCO-2297: Add test for osImageStream [#5881](https://github.com/openshift/machine-config-operator/pull/5881)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/4d59cd4cf18393469ecfdc5e89e43c8b3f427117...0df05f6ea615ec212f68633f92d01f6e248d2a34)
### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/e49b096880f17296d42a77443dc14d732683333d)
* NO-ISSUE: update BMO [#183](https://github.com/openshift/image-customization-controller/pull/183)
* [Full changelog](https://github.com/openshift/image-customization-controller/compare/7a348422137de33a9bfa6368b3797686ff4e8f98...e49b096880f17296d42a77443dc14d732683333d)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/bf618aac93c71a56e8249669c579f0a782742e2e)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Add IDMS mirror support for disconnected aarch64 ISO extraction [#108](https://github.com/openshift/machine-os-images/pull/108)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/9a06f121e75727de9b6f97231f5ca01cb16ead3b...bf618aac93c71a56e8249669c579f0a782742e2e)
### [metallb-frr](https://github.com/openshift/frr/tree/54a6ea48902d81460536b81ea6bdceb89c12e622)
* [OCPBUGS-104452](https://issues.redhat.com/browse/OCPBUGS-104452): Fix TLS ciphers for MinVersion=1.3 [#135](https://github.com/openshift/frr/pull/135)
* [Full changelog](https://github.com/openshift/frr/compare/5d3b12b6ce0a7def4a7a4d1df7ff9e88deb430f5...54a6ea48902d81460536b81ea6bdceb89c12e622)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/4f11dd62c135eb90491b00348d8b9fdc30194320)
* NO-JIRA: remove helm chart [#1126](https://github.com/openshift/monitoring-plugin/pull/1126)
* [OU-1486](https://issues.redhat.com/browse/OU-1486): feat: add art dockerfile [#1117](https://github.com/openshift/monitoring-plugin/pull/1117)
* [OCPBUGS-98488](https://issues.redhat.com/browse/OCPBUGS-98488): security: fix js-yaml vulnerable version [#1115](https://github.com/openshift/monitoring-plugin/pull/1115)
* NO-JIRA: feat: add renovate configuration [#1113](https://github.com/openshift/monitoring-plugin/pull/1113)
* [OCPBUGS-104374](https://issues.redhat.com/browse/OCPBUGS-104374): upgrade go stdlib and patch vulnerabilities [#1111](https://github.com/openshift/monitoring-plugin/pull/1111)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): fix: remove deprecation in favor of k8sListItems to fetch agentic runs [#1110](https://github.com/openshift/monitoring-plugin/pull/1110)
* [OU-1466](https://issues.redhat.com/browse/OU-1466): swap dashboard-list-page to use shared table setup [#1109](https://github.com/openshift/monitoring-plugin/pull/1109)
* NO-JIRA: don't filter silences based on namespace in acm [#1108](https://github.com/openshift/monitoring-plugin/pull/1108)
* [OCPBUGS-98877](https://issues.redhat.com/browse/OCPBUGS-98877): fix: upgrade linkify-it [#1104](https://github.com/openshift/monitoring-plugin/pull/1104)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): remove default features from plugin-backend [#1078](https://github.com/openshift/monitoring-plugin/pull/1078)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Makefile and package.json to enable test-frontend-ci [#1091](https://github.com/openshift/monitoring-plugin/pull/1091)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): add OWNERS_ALIAS and feature based OWNERS files [#1083](https://github.com/openshift/monitoring-plugin/pull/1083)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): update devspace setup [#1073](https://github.com/openshift/monitoring-plugin/pull/1073)
* NO-JIRA: build(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /web [#1084](https://github.com/openshift/monitoring-plugin/pull/1084)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): Remove Shared Dashbaords Components [#1077](https://github.com/openshift/monitoring-plugin/pull/1077)
* [OBSINTA-1290](https://issues.redhat.com/browse/OBSINTA-1290): fix incident detection test selectors [#1022](https://github.com/openshift/monitoring-plugin/pull/1022)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Dockerfile.test permission [#1076](https://github.com/openshift/monitoring-plugin/pull/1076)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): increasing node options memory [#1069](https://github.com/openshift/monitoring-plugin/pull/1069)
* [OCPBUGS-92067](https://issues.redhat.com/browse/OCPBUGS-92067): graph redirect query parameter [#1067](https://github.com/openshift/monitoring-plugin/pull/1067)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): add styleguide and file-naming rules [#1065](https://github.com/openshift/monitoring-plugin/pull/1065)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): Update Import Linting [#1062](https://github.com/openshift/monitoring-plugin/pull/1062)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): move components and utils into shared locations [#1056](https://github.com/openshift/monitoring-plugin/pull/1056)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): don't match on feature_* webpack bundles [#1061](https://github.com/openshift/monitoring-plugin/pull/1061)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): update documentation with new frontend folder structure [#1055](https://github.com/openshift/monitoring-plugin/pull/1055)
* [OU-651](https://issues.redhat.com/browse/OU-651): Fix AlertRules page to display user defined loki alerts [#1054](https://github.com/openshift/monitoring-plugin/pull/1054)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): restructure folders [#1038](https://github.com/openshift/monitoring-plugin/pull/1038)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): Match new ols routing and names [#1052](https://github.com/openshift/monitoring-plugin/pull/1052)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): feat: align proposal url with ols detail view, check multiple namespaces for proposals [#1044](https://github.com/openshift/monitoring-plugin/pull/1044)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): swap monitoring-plugin to be feature driven [#1034](https://github.com/openshift/monitoring-plugin/pull/1034)
* [OBSINTA-1006](https://issues.redhat.com/browse/OBSINTA-1006): Add UI performance benchmarks for Incidents page [#873](https://github.com/openshift/monitoring-plugin/pull/873)
* NO-JIRA: fixing unit-test severity sort, variable template regex, and test corrections. [#1035](https://github.com/openshift/monitoring-plugin/pull/1035)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/9524ff2716a6f1fcb852b30de9264b79841de67e...4f11dd62c135eb90491b00348d8b9fdc30194320)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/6d9df61378321846c00a32f0c42b6688daacd649)
* NO-JIRA: Remove TLS min version validation for OpenShift profile compatibility [#122](https://github.com/openshift/multus-admission-controller/pull/122)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/4bb2e2069c3e4f11fbc4c1befd6dc1c41fa802b7...6d9df61378321846c00a32f0c42b6688daacd649)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/f099946680e376f722674e684aec96a73c58e919)
* [OCPBUGS-86046](https://issues.redhat.com/browse/OCPBUGS-86046), [OCPBUGS-94044](https://issues.redhat.com/browse/OCPBUGS-94044): DS Merge 07/24/2026 [#335](https://github.com/openshift/multus-cni/pull/335)
* [CORENET-7233](https://issues.redhat.com/browse/CORENET-7233): Update OWNERS file [#304](https://github.com/openshift/multus-cni/pull/304)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Simplify Dockerfile to rhel9-only build [#285](https://github.com/openshift/multus-cni/pull/285)
* [Full changelog](https://github.com/openshift/multus-cni/compare/b4ec7d8239ce4bd3ed949bce9816a013377b44c7...f099946680e376f722674e684aec96a73c58e919)
### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/7a26023b1ebb3d2c6120973a97a9bed9adfae334)
* [CORENET-7235](https://issues.redhat.com/browse/CORENET-7235): Update OWNERS file [#116](https://github.com/openshift/multus-networkpolicy/pull/116)
* [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/932bdaa4250d0a1db41a1a1fcac8192f2757211c...7a26023b1ebb3d2c6120973a97a9bed9adfae334)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/d918bda28ad3d0200b6e4f2ef2801556764762e5)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Drop rhel8 builds, strip debug info [#405](https://github.com/openshift/whereabouts-cni/pull/405)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d691040e509bb20c26b5e8366c0d6f3bb45a5e02...d918bda28ad3d0200b6e4f2ef2801556764762e5)
### [must-gather](https://github.com/openshift/must-gather/tree/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
* [OCPBUGS-87538](https://issues.redhat.com/browse/OCPBUGS-87538): Updating ose-must-gather-container image to be consistent with ART for 5.0 [#553](https://github.com/openshift/must-gather/pull/553)
* [MG-247](https://issues.redhat.com/browse/MG-247): collect imagedigestmirrorsets and imagetagmirrorset resources [#538](https://github.com/openshift/must-gather/pull/538)
* [OCPBUGS-85052](https://issues.redhat.com/browse/OCPBUGS-85052): feat: add pacemaker resource to mustgather [#556](https://github.com/openshift/must-gather/pull/556)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/must-gather/compare/16ac27eedcc79f5b57d77eb01e6b187b84fe7daa...fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844)
* [OCPBUGS-87459](https://issues.redhat.com/browse/OCPBUGS-87459): Updating ose-network-metrics-daemon-container image to be consistent with ART for 5.0 [#144](https://github.com/openshift/network-metrics-daemon/pull/144)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/5b233ea1d80733c1b00c6bad65dec0620dbf783a...e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/33788405f30ef023250fd8fab71caeab57ec6b90)
* IP address & Adapter model columns [#465](https://github.com/openshift/networking-console-plugin/pull/465)
* [OCPNETUI-58](https://issues.redhat.com/browse/OCPNETUI-58): Add Health and Backend health columns to Services and Routes list pages [#457](https://github.com/openshift/networking-console-plugin/pull/457)
* [OCPNETUI-38](https://issues.redhat.com/browse/OCPNETUI-38): Virtual Machines tab on NAD/UDN/CUDN detail pages [#442](https://github.com/openshift/networking-console-plugin/pull/442)
* [OCPNETUI-21](https://issues.redhat.com/browse/OCPNETUI-21), [OCPNETUI-25](https://issues.redhat.com/browse/OCPNETUI-25): made form for creating services [#453](https://github.com/openshift/networking-console-plugin/pull/453)
* And 3 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/35f8ec76aeffeab0452e36d39488ad00ac9c22c1...33788405f30ef023250fd8fab71caeab57ec6b90)
### [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix/tree/249b7c8edfca8f25413dc76bc5a216fbe12a9ab1)
* [OCPCLOUD-3619](https://issues.redhat.com/browse/OCPCLOUD-3619): Bump k8s 1.36 [#139](https://github.com/openshift/machine-api-provider-nutanix/pull/139)
* [Full changelog](https://github.com/openshift/machine-api-provider-nutanix/compare/b8b84ebcda147113477af9a4edbcdfb03e22875c...249b7c8edfca8f25413dc76bc5a216fbe12a9ab1)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/6fe1863c424f1e69dbb7636d7531eaef06db74a9)
* [CNTRLPLANE-3947](https://issues.redhat.com/browse/CNTRLPLANE-3947): hack/update-openapi-spec: add image resolution and registry auth [#214](https://github.com/openshift/oauth-apiserver/pull/214)
* [CNTRLPLANE-2445](https://issues.redhat.com/browse/CNTRLPLANE-2445): K8s 1.35 rebase [#179](https://github.com/openshift/oauth-apiserver/pull/179)
* [CNTRLPLANE-2449](https://issues.redhat.com/browse/CNTRLPLANE-2449): feat: generate OpenAPI schemas from a running oauth-apiserver instance [#211](https://github.com/openshift/oauth-apiserver/pull/211)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/9e9722dd2f3f71ec891e3413a8a8cdd6dbfe872f...6fe1863c424f1e69dbb7636d7531eaef06db74a9)
### [oauth-server](https://github.com/openshift/oauth-server/tree/ffad196a95584670d3a2e20e270cb23a64e6a327)
* [RFE-9629](https://issues.redhat.com/browse/RFE-9629): Add copy to clipboard buttons to display token page [#200](https://github.com/openshift/oauth-server/pull/200)
* [CNTRLPLANE-2446](https://issues.redhat.com/browse/CNTRLPLANE-2446): K8s 1.35 rebase [#215](https://github.com/openshift/oauth-server/pull/215)
* [CNTRLPLANE-3751](https://issues.redhat.com/browse/CNTRLPLANE-3751): Add dynamic proxy CA reload for outbound IdP transports [#244](https://github.com/openshift/oauth-server/pull/244)
* [CNTRLPLANE-3751](https://issues.redhat.com/browse/CNTRLPLANE-3751): Rebase onto 1.35 to be able to update openshift/api [#247](https://github.com/openshift/oauth-server/pull/247)
* [Full changelog](https://github.com/openshift/oauth-server/compare/79ea885db0e910f37c9a69388df9ee06a491a0bb...ffad196a95584670d3a2e20e270cb23a64e6a327)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/49582d3d95fd5e5c8e2d232bf0d5568860514e5d)
* NO-ISSUE: Synchronize From Upstream Repositories [#788](https://github.com/openshift/operator-framework-operator-controller/pull/788)
* [OCPBUGS-89330](https://issues.redhat.com/browse/OCPBUGS-89330): Synchronize From Upstream Repositories [#779](https://github.com/openshift/operator-framework-operator-controller/pull/779)
* NO-ISSUE: Synchronize From Upstream Repositories [#776](https://github.com/openshift/operator-framework-operator-controller/pull/776)
* [OPRUN-4436](https://issues.redhat.com/browse/OPRUN-4436): fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary [#766](https://github.com/openshift/operator-framework-operator-controller/pull/766)
* [OPRUN-4659](https://issues.redhat.com/browse/OPRUN-4659), [OPRUN-4666](https://issues.redhat.com/browse/OPRUN-4666), [OPRUN-4671](https://issues.redhat.com/browse/OPRUN-4671), [OPRUN-4672](https://issues.redhat.com/browse/OPRUN-4672), [OPRUN-4673](https://issues.redhat.com/browse/OPRUN-4673), [OPRUN-4674](https://issues.redhat.com/browse/OPRUN-4674): Synchronize From Upstream Repositories + Remove spec.serviceAccount tests [#767](https://github.com/openshift/operator-framework-operator-controller/pull/767)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#769](https://github.com/openshift/operator-framework-operator-controller/pull/769)
* [OPRUN-4392](https://issues.redhat.com/browse/OPRUN-4392), [OPRUN-4393](https://issues.redhat.com/browse/OPRUN-4393): Add OLMv1 progress deadline QE tests + fixes [#755](https://github.com/openshift/operator-framework-operator-controller/pull/755)
* [OPRUN-4437](https://issues.redhat.com/browse/OPRUN-4437): test: add allow-case for operator maxOCPVersion > cluster version [#765](https://github.com/openshift/operator-framework-operator-controller/pull/765)
* NO-ISSUE: Remove HelmChartSupport feature gate from experimental manifests [#764](https://github.com/openshift/operator-framework-operator-controller/pull/764)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/c86311fbce5d931b387b4d579e0e301406ce9c86...49582d3d95fd5e5c8e2d232bf0d5568860514e5d)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/5ab4a0e0e838bcacc131819a29f257bfcca72d5d)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): hack/update-openapi-spec: add image resolution and registry auth [#667](https://github.com/openshift/openshift-apiserver/pull/667)
* [OCPBUGS-94042](https://issues.redhat.com/browse/OCPBUGS-94042): Return proper 404 when deleting a non-existent project [#671](https://github.com/openshift/openshift-apiserver/pull/671)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): hack/update-openapi-spec: prefer REGISTRY_AUTH_FILE over cluster profile pull secret [#669](https://github.com/openshift/openshift-apiserver/pull/669)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): address review feedback on project watcher [#664](https://github.com/openshift/openshift-apiserver/pull/664)
* [CNTRLPLANE-2449](https://issues.redhat.com/browse/CNTRLPLANE-2449): K8s 1.35 rebase [#616](https://github.com/openshift/openshift-apiserver/pull/616)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/00b41f2b10b173b37fb01bf71d72fcae2ff4c89a...5ab4a0e0e838bcacc131819a29f257bfcca72d5d)
### [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics/tree/3b4ea3e753d97fea66e0f52c8282a711358b4ff7)
* NO-JIRA: update Go dependencies [#135](https://github.com/openshift/openshift-state-metrics/pull/135)
* [Full changelog](https://github.com/openshift/openshift-state-metrics/compare/0e12f5d6df02b37b0353a747d144e8069c3d0c2a...3b4ea3e753d97fea66e0f52c8282a711358b4ff7)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/4f65df9309c97435fc53c05f6ea4b6135b243166)
* [OSPRH-33339](https://issues.redhat.com/browse/OSPRH-33339): Add rebasebot post-rebase hook script [#428](https://github.com/openshift/cluster-api-provider-openstack/pull/428)
* [OCPBUGS-94057](https://issues.redhat.com/browse/OCPBUGS-94057): UPSTREAM: 3265: :bug: allow unconditional providerID updates in OpenStackMachine [#425](https://github.com/openshift/cluster-api-provider-openstack/pull/425)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#424](https://github.com/openshift/cluster-api-provider-openstack/pull/424)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/76198b243458ca266eb8b87bbcf69a7b7c3eec7f...4f65df9309c97435fc53c05f6ea4b6135b243166)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/4715653291eabae5f695d198bf6663851bb00be6)
* [OCPBUGS-104542](https://issues.redhat.com/browse/OCPBUGS-104542): force same arch for opm and catalogsource pod for multiarch tests [#1344](https://github.com/openshift/operator-framework-olm/pull/1344)
* [OCPBUGS-86895](https://issues.redhat.com/browse/OCPBUGS-86895): Ensure packageserver pod seccompProfile is always set [#1341](https://github.com/openshift/operator-framework-olm/pull/1341)
* NO-ISSUE: Synchronize From Upstream Repositories [#1343](https://github.com/openshift/operator-framework-olm/pull/1343)
* NO-ISSUE: Synchronize From Upstream Repositories [#1340](https://github.com/openshift/operator-framework-olm/pull/1340)
* [OCPBUGS-96749](https://issues.redhat.com/browse/OCPBUGS-96749), [OCPBUGS-96752](https://issues.redhat.com/browse/OCPBUGS-96752): Synchronize From Upstream Repositories [#1338](https://github.com/openshift/operator-framework-olm/pull/1338)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#1339](https://github.com/openshift/operator-framework-olm/pull/1339)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/277e53cc3ad60306296e1269ea12b97c3558cfdc...4715653291eabae5f695d198bf6663851bb00be6)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/fa9e19b2ae7ad8de20b345e3bd736923f5c516cc)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 3 updates [#769](https://github.com/operator-framework/operator-marketplace/pull/769)
* NO-ISSUE: Bump github.com/prometheus/client_golang from 1.24.0 to 1.24.1 [#772](https://github.com/operator-framework/operator-marketplace/pull/772)
* NO-ISSUE: Bump github.com/operator-framework/operator-lifecycle-manager from 0.45.0 to 0.46.0 [#771](https://github.com/operator-framework/operator-marketplace/pull/771)
* NO-ISSUE: Bump github.com/operator-framework/operator-lifecycle-manager from 0.43.0 to 0.45.0 [#761](https://github.com/operator-framework/operator-marketplace/pull/761)
* NO-ISSUE: Bump dependencies to kube 1.36 [#766](https://github.com/operator-framework/operator-marketplace/pull/766)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/7e3aaeefdac17e1dd690554c9f0549319d219214...fa9e19b2ae7ad8de20b345e3bd736923f5c516cc)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/e52cd51b6537e6cabab2de24cd4bd65254ebd09f)
* [OCPBUGS-100275](https://issues.redhat.com/browse/OCPBUGS-100275), [OCPBUGS-85627](https://issues.redhat.com/browse/OCPBUGS-85627): DownStream Merge [08-10-2026] [#3361](https://github.com/openshift/ovn-kubernetes/pull/3361)
* NO-JIRA: openshift: fix lint issues [#3301](https://github.com/openshift/ovn-kubernetes/pull/3301)
* [CORENET-7229](https://issues.redhat.com/browse/CORENET-7229): OTE: Add test list validation tooling [#3221](https://github.com/openshift/ovn-kubernetes/pull/3221)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove RHEL 8 binary build [#3149](https://github.com/openshift/ovn-kubernetes/pull/3149)
* [OCPBUGS-87283](https://issues.redhat.com/browse/OCPBUGS-87283), [OCPBUGS-87530](https://issues.redhat.com/browse/OCPBUGS-87530), [OCPBUGS-87532](https://issues.redhat.com/browse/OCPBUGS-87532), [OCPBUGS-93623](https://issues.redhat.com/browse/OCPBUGS-93623), [OCPBUGS-95512](https://issues.redhat.com/browse/OCPBUGS-95512), [OCPBUGS-98138](https://issues.redhat.com/browse/OCPBUGS-98138): DownStream Merge [07-31-2026] [#3332](https://github.com/openshift/ovn-kubernetes/pull/3332)
* [OCPBUGS-65865](https://issues.redhat.com/browse/OCPBUGS-65865), [OCPBUGS-86223](https://issues.redhat.com/browse/OCPBUGS-86223), [OCPBUGS-89327](https://issues.redhat.com/browse/OCPBUGS-89327): DownStream Merge [07-17-2026] [#3298](https://github.com/openshift/ovn-kubernetes/pull/3298)
* NO-JIRA: Update OWNERS File [#3288](https://github.com/openshift/ovn-kubernetes/pull/3288)
* NO-JIRA: DownStream Merge [07-02-2026] [#3279](https://github.com/openshift/ovn-kubernetes/pull/3279)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/fc46681bd5720c0139c394eea3d2ab686a2cf46f...e52cd51b6537e6cabab2de24cd4bd65254ebd09f)
### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/f90431bfe8ca93850450b2b24fae152d2385ca08)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#119](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/119)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/ab04496a6855098853048c957c499f2a63200f8e...f90431bfe8ca93850450b2b24fae152d2385ca08)
### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/18eb5238fb2c86632edb24175f536d815f28ddf6)
* No-Jira: Bump cel-go to v0.29.0, grpc to v1.82.1 and x/text to v0.39.0 to address security vulnerabilities [#107](https://github.com/openshift/cloud-provider-powervs/pull/107)
* [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/626c77c1b8c4b81b2d2f775f98f740dc09648061...18eb5238fb2c86632edb24175f536d815f28ddf6)
### [prometheus](https://github.com/openshift/prometheus/tree/01d8335673aa6f88f5742ef510e133efee88a7bf)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.13.2 [#351](https://github.com/openshift/prometheus/pull/351)
* [OCPBUGS-100192](https://issues.redhat.com/browse/OCPBUGS-100192): [bot] Bump openshift/prometheus to v3.13.2 [#350](https://github.com/openshift/prometheus/pull/350)
* Bump openshift/prometheus to v3.13.1 [#347](https://github.com/openshift/prometheus/pull/347)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.13.1 [#345](https://github.com/openshift/prometheus/pull/345)
* NO-JIRA: chore: revert narrow selectors detection for le/quantile labels [#344](https://github.com/openshift/prometheus/pull/344)
* [Full changelog](https://github.com/openshift/prometheus/compare/fb9f64e2410f196d83761048726ed94802f6b8f0...01d8335673aa6f88f5742ef510e133efee88a7bf)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
* [OCPBUGS-104610](https://issues.redhat.com/browse/OCPBUGS-104610): bump dependencies from the golang-org-x group [#156](https://github.com/openshift/prometheus-alertmanager/pull/156)
* [OCPBUGS-98190](https://issues.redhat.com/browse/OCPBUGS-98190): bump github.com/hashicorp/memberlist from 0.5.4 to 0.6.0 [#155](https://github.com/openshift/prometheus-alertmanager/pull/155)
* [OCPBUGS-99435](https://issues.redhat.com/browse/OCPBUGS-99435): embed tzdata in the alertmanager binary [#140](https://github.com/openshift/prometheus-alertmanager/pull/140)
* Bump openshift/prometheus-alertmanager to v0.33.1 [#139](https://github.com/openshift/prometheus-alertmanager/pull/139)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/c30580cbb1af27356599c785720ee5043440e84a...89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/67895c7c968f42e97efec58f4140fffae4832028)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.1 [#391](https://github.com/openshift/prometheus-operator/pull/391)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.0 [#388](https://github.com/openshift/prometheus-operator/pull/388)
* [OCPBUGS-96853](https://issues.redhat.com/browse/OCPBUGS-96853): [bot] Bump openshift/prometheus-operator to v0.92.1 [#385](https://github.com/openshift/prometheus-operator/pull/385)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/6a36acbd5ecd5a308bc81267f3b0567f93377247...67895c7c968f42e97efec58f4140fffae4832028)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
* [OCPBUGS-100376](https://issues.redhat.com/browse/OCPBUGS-100376): fibre_channel: fix crash when attempting to dereference invalid countโฆ [#183](https://github.com/openshift/node_exporter/pull/183)
* [MON-4614](https://issues.redhat.com/browse/MON-4614): [bot] Bump openshift/node_exporter to v1.12.1 [#182](https://github.com/openshift/node_exporter/pull/182)
* [Full changelog](https://github.com/openshift/node_exporter/compare/45dec4ebf58ec9fb7083411ee4b6d46c01140c5f...4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/59697cf7af4517dd44e28179a57f7f35b6ea0e22)
* [NE-2767](https://issues.redhat.com/browse/NE-2767): Bump Kubernetes to 1.36.2 [#100](https://github.com/openshift/route-controller-manager/pull/100)
* [OCPBUGS-92032](https://issues.redhat.com/browse/OCPBUGS-92032): Dockerfile: Copy only build-required files in builder stage [#99](https://github.com/openshift/route-controller-manager/pull/99)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/01ccbfb991fdbc559820a04c4932fc5ddf2339d0...59697cf7af4517dd44e28179a57f7f35b6ea0e22)
### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/ed872ba14b615ca5726ae90e987268877a0b0b20)
* [CNTRLPLANE-3898](https://issues.redhat.com/browse/CNTRLPLANE-3898): Bump kubernetes dependencies to v1.36.2 [#366](https://github.com/openshift/service-ca-operator/pull/366)
* [MON-4515](https://issues.redhat.com/browse/MON-4515): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#319](https://github.com/openshift/service-ca-operator/pull/319)
* [OCPBUGS-87390](https://issues.redhat.com/browse/OCPBUGS-87390): Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 [#361](https://github.com/openshift/service-ca-operator/pull/361)
* NO-JIRA: Bump github.com/openshift/build-machinery-go [#367](https://github.com/openshift/service-ca-operator/pull/367)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into service-ca operand [#365](https://github.com/openshift/service-ca-operator/pull/365)
* [Full changelog](https://github.com/openshift/service-ca-operator/compare/6391e070d2ab026324b032a6fa5fc7d6be0d2cb5...ed872ba14b615ca5726ae90e987268877a0b0b20)
### [stream-coreos, stream-coreos-extensions](https://github.com/openshift/os/tree/bf90b219ae4ba42e07bf8c010b725401b5402cc8)
* Revert "Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS"" [#1955](https://github.com/openshift/os/pull/1955)
* Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS" [#1954](https://github.com/openshift/os/pull/1954)
* [OCPBUGS-104572](https://issues.redhat.com/browse/OCPBUGS-104572): NetworkManager-ovs has moved up to RHCOS [#1952](https://github.com/openshift/os/pull/1952)
* [Full changelog](https://github.com/openshift/os/compare/5ffc1da076e834332482544182c22d984dbf76d2...bf90b219ae4ba42e07bf8c010b725401b5402cc8)
### [tests](https://github.com/openshift/origin/tree/5cddf6d79a095fd5ebaefc96a195531fc39d5a9b)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate OTE for Pull Secrets, Feature Gates and Webhooks [#31382](https://github.com/openshift/origin/pull/31382)
* [OCPBUGS-105768](https://issues.redhat.com/browse/OCPBUGS-105768): Update s2i_images test for OCP samples sync [#31504](https://github.com/openshift/origin/pull/31504)
* [OCPBUGS-98719](https://issues.redhat.com/browse/OCPBUGS-98719): retry GetVotingMemberNames on transient etcd client fails [#31445](https://github.com/openshift/origin/pull/31445)
* [OCPBUGS-105466](https://issues.redhat.com/browse/OCPBUGS-105466): monitortests: recognize PascalCase TNF JobRunning CO reasons [#31499](https://github.com/openshift/origin/pull/31499)
* [OCPEDGE-2700](https://issues.redhat.com/browse/OCPEDGE-2700): fix flaky etcd disruption tests and remove unreliable is_standalone test [#31276](https://github.com/openshift/origin/pull/31276)
* [OCPNODE-4623](https://issues.redhat.com/browse/OCPNODE-4623): e2e for Block runc on RHEL 10 via OSImageURL stream class inspection [#31433](https://github.com/openshift/origin/pull/31433)
* [OCPBUGS-104544](https://issues.redhat.com/browse/OCPBUGS-104544): tolerate one NotReady CP node in EnsureNodesReady for degraded TNF [#31442](https://github.com/openshift/origin/pull/31442)
* [OCPNODE-4521](https://issues.redhat.com/browse/OCPNODE-4521): Use programmatic skip for single-node instead of test name tag [#31486](https://github.com/openshift/origin/pull/31486)
* NO-ISSUE: Consider centos-10 stream for OKD clusters [#31487](https://github.com/openshift/origin/pull/31487)
* [OCPBUGS-84491](https://issues.redhat.com/browse/OCPBUGS-84491): Remove openshift-ingress terminationMessagePolicy exemption [#31435](https://github.com/openshift/origin/pull/31435)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): remove storage NetworkPolicies from validation skip list [#31429](https://github.com/openshift/origin/pull/31429)
* NO-ISSUE: Skip Additional Storage tests on HyperShift - MachineConfig API not available [#31489](https://github.com/openshift/origin/pull/31489)
* [NE-2788](https://issues.redhat.com/browse/NE-2788): exempt ingress Upgradeable=False for deprecated HAProxy versions [#31494](https://github.com/openshift/origin/pull/31494)
* NO-JIRA: Remove Istio configmap workaround from ClusterResourceQuota test [#31444](https://github.com/openshift/origin/pull/31444)
* [OCPEDGE-2787](https://issues.redhat.com/browse/OCPEDGE-2787): fix: skip MCPs with non-ready nodes during MCN property validation [#31380](https://github.com/openshift/origin/pull/31380)
* [OCPEDGE-2785](https://issues.redhat.com/browse/OCPEDGE-2785): fix: adjusting DaemonSet test to dynamically compute expected pod count [#31378](https://github.com/openshift/origin/pull/31378)
* [OCPCLOUD-3074](https://issues.redhat.com/browse/OCPCLOUD-3074): Validate Azure dual-stack load balancers [#31452](https://github.com/openshift/origin/pull/31452)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate tests of Prometheus, Audit and TLS to OTE [#31360](https://github.com/openshift/origin/pull/31360)
* [TRT-2618](https://issues.redhat.com/browse/TRT-2618): Add env var support to selectively enable resource monitor tests and event collection [#31420](https://github.com/openshift/origin/pull/31420)
* Bug OCPBUGS-104497: Fix [sig-ci] prow job name OS version test for 4.23 rhcos9 [#31481](https://github.com/openshift/origin/pull/31481)
* [OCPBUGS-100392](https://issues.redhat.com/browse/OCPBUGS-100392): Exclude openshift-debug-* namespaces from CPU Partitioning annotation check [#31465](https://github.com/openshift/origin/pull/31465)
* NO-ISSUE: Automated - Update synthetic test data [#31459](https://github.com/openshift/origin/pull/31459)
* Revert "TRT-2869: Revert "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO"" [#31462](https://github.com/openshift/origin/pull/31462)
* [OCPBUGS-101912](https://issues.redhat.com/browse/OCPBUGS-101912): derive cluster quota from namespace configmaps [#31476](https://github.com/openshift/origin/pull/31476)
* [STOR-3065](https://issues.redhat.com/browse/STOR-3065): Add storage CSI tests for cloning PVC to a larger volume [#31443](https://github.com/openshift/origin/pull/31443)
* [OCPBUGS-100386](https://issues.redhat.com/browse/OCPBUGS-100386): test: scope hosted etcd leader metrics by namespace [#31456](https://github.com/openshift/origin/pull/31456)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Remove NLB hairpin workaround from dual-stack test [#31453](https://github.com/openshift/origin/pull/31453)
* [OCPBUGS-99899](https://issues.redhat.com/browse/OCPBUGS-99899): add os name exception for runc jobs [#31479](https://github.com/openshift/origin/pull/31479)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Adding netobserv namespace exception for prometheus endpoint auth [#31447](https://github.com/openshift/origin/pull/31447)
* [OCPBUGS-100388](https://issues.redhat.com/browse/OCPBUGS-100388): Fix project name collision in test framework [#31464](https://github.com/openshift/origin/pull/31464)
* [OCPBUGS-100385](https://issues.redhat.com/browse/OCPBUGS-100385): MonitorTest: measure the union of ClusterOperator wait intervals [#31457](https://github.com/openshift/origin/pull/31457)
* [OCPBUGS-99397](https://issues.redhat.com/browse/OCPBUGS-99397): remove custom MCP and pause master pool in mirror-set tests to prevent PDB drain deadlock and suite timeout [#31408](https://github.com/openshift/origin/pull/31408)
* Revert: Fix APIs for openshift.io must have stable versions check [#31468](https://github.com/openshift/origin/pull/31468)
* [OCPBUGS-99916](https://issues.redhat.com/browse/OCPBUGS-99916): exclude openshift-debug-* namespaces from best-effort QoS invariant [#31437](https://github.com/openshift/origin/pull/31437)
* [TRT-2869](https://issues.redhat.com/browse/TRT-2869): Revert #31440 "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO" [#31460](https://github.com/openshift/origin/pull/31460)
* [OCPBUGS-100308](https://issues.redhat.com/browse/OCPBUGS-100308): Fix test `APIs for openshift.io must have stable versions` [#31458](https://github.com/openshift/origin/pull/31458)
* [OCPBUGS-99047](https://issues.redhat.com/browse/OCPBUGS-99047): Fix flaky oc adm storage-admin test [#31400](https://github.com/openshift/origin/pull/31400)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): [TNF] Fix update-setup job discovery to limit check to active job [#31451](https://github.com/openshift/origin/pull/31451)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Dump istiod logs and gateway state on GatewayAPI test failure [#31454](https://github.com/openshift/origin/pull/31454)
* NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO [#31440](https://github.com/openshift/origin/pull/31440)
* [OCPBUGS-100183](https://issues.redhat.com/browse/OCPBUGS-100183): Always tear down upgrade tests after setup failures [#31450](https://github.com/openshift/origin/pull/31450)
* [OCPBUGS-98576](https://issues.redhat.com/browse/OCPBUGS-98576): Improve test output for nodes should be ready test [#31419](https://github.com/openshift/origin/pull/31419)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): handle bookmark events in project watch tests [#31313](https://github.com/openshift/origin/pull/31313)
* NO-JIRA: Update minio image to use source with all supported architectures [#31441](https://github.com/openshift/origin/pull/31441)
* [OCPBUGS-85529](https://issues.redhat.com/browse/OCPBUGS-85529): Fix IPv6 prefix in MultiNetworkPolicy test (/32 โ /64) [#31407](https://github.com/openshift/origin/pull/31407)
* [OCPBUGS-99535](https://issues.redhat.com/browse/OCPBUGS-99535): Skip Squid proxy configuration [#31423](https://github.com/openshift/origin/pull/31423)
* NO-ISSUE: Skip additional storage support E2E test for on single-node - MCP rollouts timeout [#31439](https://github.com/openshift/origin/pull/31439)
* [CNTRLPLANE-3789](https://issues.redhat.com/browse/CNTRLPLANE-3789): images: Add squid image used in CAO e2e tests [#31434](https://github.com/openshift/origin/pull/31434)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Skip tests temporarily for the new output of the recommend cmd [#31417](https://github.com/openshift/origin/pull/31417)
* [STOR-3063](https://issues.redhat.com/browse/STOR-3063): Add GCP regional PD e2e test for cross-zone data sync [#31416](https://github.com/openshift/origin/pull/31416)
* [CNTRLPLANE-3741](https://issues.redhat.com/browse/CNTRLPLANE-3741): PKI config tests for service-ca and kube-apiserver-operator [#31341](https://github.com/openshift/origin/pull/31341)
* NO-JIRA: Replace a bug id: 25739 -> 92835 [#31345](https://github.com/openshift/origin/pull/31345)
* [OCPNODE-4055](https://issues.redhat.com/browse/OCPNODE-4055): Add e2e testcase for additional storage support feature [#31399](https://github.com/openshift/origin/pull/31399)
* NO-ISSUE: Automated - Update synthetic test data [#31260](https://github.com/openshift/origin/pull/31260)
* [OCPNODE-4494](https://issues.redhat.com/browse/OCPNODE-4494): e2e test case for RHCOS upgrade from 9 โ 10 [#31393](https://github.com/openshift/origin/pull/31393)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#31237](https://github.com/openshift/origin/pull/31237)
* [NE-2789](https://issues.redhat.com/browse/NE-2789): Add a guard to skip IngressControllerMultipleHAProxyVersions tests if IngressController CRD lacks haproxyVersion field [#31424](https://github.com/openshift/origin/pull/31424)
* NO-JIRA: chore(extended/prometheus): reduce targets-auth skip list and handle mTLS [#31372](https://github.com/openshift/origin/pull/31372)
* NO-JIRA: Ensure Platform Prometheus targets are not scraped with insecure_skip_verify [#31373](https://github.com/openshift/origin/pull/31373)
* NO-JIRA: Add e2e test to detect named ports in NetworkPolicies [#31375](https://github.com/openshift/origin/pull/31375)
* [OCPQUAL-20](https://issues.redhat.com/browse/OCPQUAL-20): Regenerate retry allowlist from 5.0 CI data [#31411](https://github.com/openshift/origin/pull/31411)
* [OCPBUGS-87079](https://issues.redhat.com/browse/OCPBUGS-87079): Add polling and longer waits in the EgressFirewall tests to avoid flakiness [#31376](https://github.com/openshift/origin/pull/31376)
* [NE-2789](https://issues.redhat.com/browse/NE-2789): Create 5 e2e test cases to help graduate the featuregate: IngressControllerMultipleHAProxyVersions [#31392](https://github.com/openshift/origin/pull/31392)
* [OCPBUGS-85696](https://issues.redhat.com/browse/OCPBUGS-85696): Adding logs and exponential backoff on execPod [#31352](https://github.com/openshift/origin/pull/31352)
* NO-JIRA: .devcontainer: bump Fedora base image to 44 for Go 1.26 [#31413](https://github.com/openshift/origin/pull/31413)
* [CONSOLE-5209](https://issues.redhat.com/browse/CONSOLE-5209): Add e2e tests for IngressComponentRouteLabels feature gate [#31385](https://github.com/openshift/origin/pull/31385)
* [OCPNODE-4538](https://issues.redhat.com/browse/OCPNODE-4538): Add e2e tests for DRA Partitionable Devices (KEP-4815) [#31230](https://github.com/openshift/origin/pull/31230)
* [TRT-2689](https://issues.redhat.com/browse/TRT-2689): Add `verify-apm` to the `verify` target [#31379](https://github.com/openshift/origin/pull/31379)
* [OCPBUGS-99166](https://issues.redhat.com/browse/OCPBUGS-99166): wait for default ServiceAccount before creating IRI test pod [#31401](https://github.com/openshift/origin/pull/31401)
* [MCO-2371](https://issues.redhat.com/browse/MCO-2371): Add back "should match os version" test [#31301](https://github.com/openshift/origin/pull/31301)
* [AGENT-1522](https://issues.redhat.com/browse/AGENT-1522): bump InternalReleaseImage to v1 [#31294](https://github.com/openshift/origin/pull/31294)
* NO-ISSUE: Fix longrunning suite for node test cases [#31339](https://github.com/openshift/origin/pull/31339)
* NO-ISSUE: Always emit precondition validation synthetic test entry [#31388](https://github.com/openshift/origin/pull/31388)
* [OCPBUGS-98956](https://issues.redhat.com/browse/OCPBUGS-98956): use admin-client namespace creation for IRI workload test [#31394](https://github.com/openshift/origin/pull/31394)
* [OCPNODE-4055](https://issues.redhat.com/browse/OCPNODE-4055): Add Additional Storage Support - API validation test cases [#31384](https://github.com/openshift/origin/pull/31384)
* NO-ISSUE: Remove Feature:NodeSwap tag and update README selectors [#31389](https://github.com/openshift/origin/pull/31389)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): allow registry.redhat.io reboot requried test [#31383](https://github.com/openshift/origin/pull/31383)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): upgrade to test v1 CRIOCredentialProviderConfig [#31324](https://github.com/openshift/origin/pull/31324)
* [Full changelog](https://github.com/openshift/origin/compare/0f64c4954e83d3cd781f656464d167cc3a79f502...5cddf6d79a095fd5ebaefc96a195531fc39d5a9b)
### [thanos](https://github.com/openshift/thanos/tree/75fa632b483716e53aec19f6adf7d4c4652a4453)
* [OCPBUGS-104611](https://issues.redhat.com/browse/OCPBUGS-104611): vendor: bump vulnerable Go dependencies for CVE remediation [#198](https://github.com/openshift/thanos/pull/198)
* NO-JIRA: [bot] Bump openshift/thanos to v0.42.4 [#196](https://github.com/openshift/thanos/pull/196)
* NO-ISSUE: [bot] Bump openshift/thanos to v0.42.3 [#195](https://github.com/openshift/thanos/pull/195)
* [OCPBUGS-97627](https://issues.redhat.com/browse/OCPBUGS-97627): [bot] Bump openshift/thanos to v0.42.2 [#194](https://github.com/openshift/thanos/pull/194)
* NO-JIRA: chore: revert narrow selectors detection for le/quantile labels [#193](https://github.com/openshift/thanos/pull/193)
* [Full changelog](https://github.com/openshift/thanos/compare/779d690da4fafe809a689f02e889e6fd9ffd4405...75fa632b483716e53aec19f6adf7d4c4652a4453)
### [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator/tree/ee9cd7aba4e096a9a957386ef20777e8950df352)
* [STOR-2917](https://issues.redhat.com/browse/STOR-2917): Rebase to v1.7.0 for OCP 5.0 [#16](https://github.com/openshift/volume-data-source-validator/pull/16)
* [Full changelog](https://github.com/openshift/volume-data-source-validator/compare/a6c21eee63d1fae58b63d8493aeb0fd662d1c91e...ee9cd7aba4e096a9a957386ef20777e8950df352)
### [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere/tree/eb29de194594bad8e5bc572102f1008cb26655a7)
* [OCPCLOUD-3596](https://issues.redhat.com/browse/OCPCLOUD-3596): Merge https://github.com/kubernetes/cloud-provider-vsphere:master (ed5683c) into main [#118](https://github.com/openshift/cloud-provider-vsphere/pull/118)
* [Full changelog](https://github.com/openshift/cloud-provider-vsphere/compare/a15538776eb26d20ab2969740cee25f9b4442302...eb29de194594bad8e5bc572102f1008cb26655a7)
### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/557fdf1a9a3540d9aa8f3a81e4a950673a416a80)
* ๐ OCPCLOUD-3604: Merge https://github.com/kubernetes-sigs/cluster-api-provider-vsphere:v1.16.1 (5b57d1d) into main [#112](https://github.com/openshift/cluster-api-provider-vsphere/pull/112)
* ๐ OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#114](https://github.com/openshift/cluster-api-provider-vsphere/pull/114)
* [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/cd9a63d6ef3eedebc687ec6b675db1a1ad947ebb...557fdf1a9a3540d9aa8f3a81e4a950673a416a80)
### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/aa27946700642a9c8e518e130673097b38a2f8bb)
* [STOR-3062](https://issues.redhat.com/browse/STOR-3062): Remove the validation webhook [#351](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/351)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#350](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/350)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/030ff0e326205bcacaddb901d6b3cb6ab4db63dd...aa27946700642a9c8e518e130673097b38a2f8bb)
### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/14a2d33817c1ddd1d753cc76decea059376e30c9)
* [OCPBUGS-87906](https://issues.redhat.com/browse/OCPBUGS-87906): Fixed GetVCenter to handle removed FDs better [#224](https://github.com/openshift/vsphere-problem-detector/pull/224)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#226](https://github.com/openshift/vsphere-problem-detector/pull/226)
* [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/34586ec43cc2a94c098ac27cf0f2b89f1460b323...14a2d33817c1ddd1d753cc76decea059376e30c9)