Releases: grafana/loki
Releases · grafana/loki
Release list
v3.7.7
3.7.7 (2026-08-27)
Features
- Add flag to ignore missing chunks during deletion of logs with line filter [release-3.7.x] (#24233) (7a40404)
Bug Fixes
- security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.2.5 [SECURITY] (release-3.7.x) (#24097) (07cd1f0)
- security/UNKNOWN/: Update module go.etcd.io/etcd/client/pkg/v3 to v3.6.14 [SECURITY] (release-3.7.x) (#24061) (9d1c9ee)
- security/UNKNOWN/: Update module golang.org/x/mod to v0.40.0 [SECURITY] (release-3.7.x) (#23962) (1d5e027)
- storage: Pre-compute SHA-256 to avoid aws-chunked on PutObject [release-3.7.x] (#24215) (3d6f245)
v3.6.16
operator: v0.11.0
0.11.0 (2026-08-18)
⚠ BREAKING CHANGES
- Remove support for experimental LogQL variants() queries (#23823)
Features
- operator: Enable multi-variant queries (#21009) (709e318)
- operator: Support private VPC S3 endpoints in endpoint validation (#22395) (394caef)
- operator: Watch object storage Services for NetworkPolicy updates and surface ports in status (#22436) (12822d5)
- Remove support for experimental LogQL variants() queries (#23823) (132e5f9)
Bug Fixes
- operator: Move telemetry recording rules to OpenShift bundle (#22814) (4632368)
- operator: Release leader lease on shutdown so upgrades are faster (#24042) (ee0d59d)
- operator: Use ruler remote_write clients key instead of deprecated client (#23455) (f5ddb02)
- security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (main) (#23608) (e1e4e0e)
- security/UNKNOWN/operator: Update module golang.org/x/net to v0.56.0 [SECURITY] (main) (#23388) (9362a5e)
- security/UNKNOWN/operator: Update module golang.org/x/text to v0.39.0 [SECURITY] (main) (#23389) (50589e1)
v3.7.6
v3.7.5
3.7.5 (2026-08-05)
Bug Fixes
- Build deb/rpm packages again in the release workflow (#23598) (6f49272)
- ci: Disable docker plugin publishing on release-3.7.x (#23440) (6095f71)
- ingester: Fix flush race in ingester [release-3.7.x] (#23682) (ff152dc)
- security/UNKNOWN/cmd/chunks-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) (#23611) (11c4b29)
- security/UNKNOWN/cmd/dataobj-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) (#23612) (1e3108e)
- security/UNKNOWN/cmd/dataobj-inspect: Update module go.opentelemetry.io/otel to v1.42.0 [SECURITY] (release-3.7.x) (#23518) (28917d3)
- security/UNKNOWN/cmd/dataobj-inspect: Update module golang.org/x/text to v0.39.0 [SECURITY] (release-3.7.x) (#23419) (5d2b9d4)
- security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) (#23613) (8d71c59)
- security/UNKNOWN/: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) (#23610) (941b557)
- security/UNKNOWN/: Update module golang.org/x/text to v0.39.0 [SECURITY] (release-3.7.x) (#23418) (2347a9a)
- security/UNKNOWN/: Update module google.golang.org/grpc to v1.82.1 [SECURITY] (release-3.7.x) (#23405) (f290af0)
v3.6.15
v3.6.14
3.6.14 (2026-08-04)
Bug Fixes
- Backport WAL replay hang fix to release-3.6.x (#21176) (#23630) (355e2f3)
- ci: Backport deb/rpm packaging fix to release-3.6.x (#23680) (#23722) (d7ee4de)
- security/UNKNOWN/cmd/chunks-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) (#23615) (a6cc2e5)
- security/UNKNOWN/cmd/dataobj-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) (#23616) (a71c910)
- security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) (#23618) (59970a9)
- security/UNKNOWN/: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) (#23614) (8308a12)
v3.6.13
3.6.13 (2026-07-23)
Bug Fixes
- ci: Fix zizmor findings for operator-images in Loki 3.6 (#22821) (050f742)
- ci: Helm CI warning fix (#22606) (4bc2586)
- security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.6.x) (#22694) (692f2b1)
- security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23398) (fc478e1)
- security/HIGH/pkg/push: Update module google.golang.org/grpc to v1.82.1 [SECURITY] (70f75b7)
- security/HIGH/: Update golang.org/x/net, golang.org/x/text and google.golang.org/grpc [SECURITY] (70f75b7)
- security/UNKNOWN/cmd/chunks-inspect: Update go toolchain directive to v1.25.12 [SECURITY] (release-3.6.x) (#23131) (b327439)
- security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.56.0 [SECURITY] (70f75b7)
- security/UNKNOWN/pkg/push: Update module golang.org/x/text to v0.39.0 [SECURITY] (70f75b7)
- security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.6.x) (#22479) (697bd83)
- security: Backport security updates to release-3.6.x (#23403) (70f75b7)
- Update objstore to include fix for GCS Exists (#23381) (87383d8)
v3.7.4
3.7.4 (2026-07-22)
Bug Fixes
- ci: Fix zizmor findings for operator-images in Loki 3.7 (#22820) (abc1186)
- ci: Helm CI warning fix (#22605) (7389428)
- ci: Re-enable docker plugin publishing (#22818) (28f44a8)
- compactor: Fix delete request when using Thanos objstore client with filesystem backend [release-3.7.x] (#22811) (dd6fdb5)
- deps: Update module charm.land/bubbletea/v2 to v2.0.7 (release-3.7.x) (#22768) (e11f935)
- deps: Update module charm.land/lipgloss/v2 to v2.0.4 (release-3.7.x) (#22769) (10213c2)
- deps: Update module github.com/aws/aws-sdk-go-v2/credentials to v1.19.24 (release-3.7.x) (#22776) (3daf198)
- deps: Update module github.com/aws/smithy-go to v1.27.3 (release-3.7.x) (#22795) (1f6a191)
- deps: Update module github.com/baidubce/bce-sdk-go to v0.9.270 (release-3.7.x) (#22783) (103ccd8)
- deps: Update module github.com/coder/quartz to v0.3.1 (release-3.7.x) (#22784) (3509e31)
- deps: Update module github.com/IBM/ibm-cos-sdk-go to v1.14.1 (release-3.7.x) (#22785) (d0abe72)
- deps: Update module github.com/klauspost/compress to v1.18.6 (release-3.7.x) (#22797) (327da7c)
- deps: Update module github.com/pierrec/lz4/v4 to v4.1.27 (release-3.7.x) (#22798) (6b3297f)
- deps: Update module github.com/shirou/gopsutil/v4 to v4.26.5 (release-3.7.x) (#22800) (cb7f17d)
- security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.7.x) (#22693) (6d8f1b5)
- security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23393) (b318f28)
- security/HIGH/: Update module github.com/apache/thrift to v0.24.0 [SECURITY] (release-3.7.x) (#22767) (36eb5f7)
- security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.55.0 [SECURITY] (release-3.7.x) (#22200) (dd7a124)
- security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.7.x) (#22478) (6fa6165)
- storage: Fix index filename issue with legacy S3 client and
chunk_delimiter(#23165) (0eca83c)
v3.7.3
3.7.3 (2026-06-24)
⚠ BREAKING CHANGES
- operator: switch default for OpenShift stream labels (#21001)
Features
- add bloom filter to cache known streams for ExceedsLimits requests (#20823) (f5440a3)
- add builder pool to logsobj package (#21134) (8a68101)
- add case-insensitive regex optimization (#20578) (f6a6a4f)
- Add config to delegate stream limits check to limits-service only (#21007) (ba119f6)
- add flush manager to control data object flush lifecycle (#20680) (c169ce3)
- add GroupConsumer to kafkav2 package (#20748) (5ad60ee)
- Add results cache to thor query engine (#20986) (6ef3827)
- Add SubstringInsensitive compute fn (#20584) (9c03192)
- Align start time when the query is received (#20967) (8e18f10)
- allow the initial offset to be set in the starting phase (#20770) (93f4bdf)
- Batch records before writing to sinks (#20821) (f083618)
- bench: add simulated object storage latency to LogQL benchmarks (#20733) (5102ed0)
- build: Move to Go 1.26 (#20988) (4fb960c)
- close the records chan when consumer terminates (#20761) (c3d0de9)
- dataobj-compactor: add a planner for compaction of data objects (#20527) (7f1450d)
- don't shuffle shard if shard factor is 1 (#21190) (7ac1d16)
- early goldfish correlation ID generation with X-Loki-Goldfish-ID header (#21155) (e90e4a6)
- engine: Dedupe entries when building final result (#21034) (e95137a)
- enginev2: Implement IsMember compute function (#20689) (a28d8b4)
- enginev2: Implement regexp compute function (#20642) (7b8d51b)
- enginev2: Implement substr compute function (#20641) (9740619)
- helm: Add common labels to all resources (#20269) (dc21099)
- helm: allow customization of write, read and backend PDB (#16871) (9f653b1)
- helm: finalize chart fork (#21166) (33f7a1b)
- helm: Memcached: allow to override CPU in the auto-computed resource mode (#20767) (3886548)
- Introduce a rate batcher to batch rate updates (#20784) (b9a0a15)
- limits: Add emptiness check to prepare for multiAZ (#20927) (4eeb70c)
- loki-query-engine: instrument query-engine with runtime/trace (#21000) (a7c75a6)
- loki: allow disabling cache for query_range requests (#21112) (1242aa5)
- operator: add option to customize gateway server cert (#20325) (3c8b9e8)
- operator: switch default for OpenShift stream labels (#21001) (61ec040)
- operator: Update Loki operand to v3.6.5 (#20696) (d81e977)
- operator: update metrics authentication to remove dependency on kube-rbac-proxy (#20853) (2de6e79)
- put kotel behind a flag (#20933) (f8e2d64)
- query-engine: Omit labels with empty values (#21173) (5c17103)
- refactor frontend cache, add metrics, filter out cached streams (#20860) (a63f0c3)
- release 3.7 (#21270) (21d5b59)
- Remove Promtail support (backport k299) (#21248) (939d15f)
- reset the consumption lag gauge after 1 minute of idle period (#20616) (f1d0cdf)
- separate metastore events and offsets from flushes (#20605) (cb938d0)
- Update references to v3.7.0 (backport k299) (#21274) (3361de2)
- Update to go 1.25.7 (#20694) (3a6ba0d)
- use stream sharding within segment subrings (#21181) (2def797)
- V2 query engine limits (#20549) (7151be7)
Bug Fixes
- Add build tags to Promtail build commands (#19989) (5596bdc)
- alloc: set a limit on preallocations (#20891) (9525e53)
- allow blocking multiple query hashes (#21103) (4c645c6)
- backoff if no records returned, instead of at least one error (#20747) (eab506d)
- broken get and replace for s3 client (#21163) ([e6abd15](h...