This is a preview — how argo-cd's changelog would look hosted on Wakelog (99 entries found, first 15 shown). Nothing was saved. To make it real: sign up (30 seconds, no email), create a project, and paste the same URL in the Import box — you'll also get RSS, an embeddable widget, a README badge, and an API. Try another.

argo-cd

v3.6.0-rc1 (pre-release)

Sep 16, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.6.0-rc1/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.6.0-rc1/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Features
  • bac4616ca429ba92af1b312cb8a2cac36e1cfdea: feat(actions): add hibernate/rehydrate actions for CNPG Cluster (#28478) (@purisev)
  • 0df1a4bcced9a8400d6ddafaf168e6e847209ec8: feat(appset): Add progressive sync metrics for AppSet (#29202) (@ranakan19)
  • ad23d3a9c04134f42661b5cbdb5aaeac46a1cdad: feat(appset): Adding annotations on apps to force reconciliation before proceeding with progressive sync (#27467) (@ranakan19)
  • 94564eba18592d1bc2fc20e64415c9214203a5d4: feat(appset): add metrics for count of app refreshes triggered by appset during progressive sync (#29244) (@ranakan19)
  • 9ef034e688e86f45fa63465710d5883d88c2ddde: feat(appset): expose workqueue rate limiter flags on applicationset-controller (#28286) (@om7057)
  • 5899f89f745513f324ff0999cf7770821b7b7fd0: feat(appset): surface progressive sync scenario into condition as reasons and messages (#27820) (@ranakan19)
  • 4e8ea39ca215a7f4c4df2d159dc3a88a8e60d994: feat(ci): enable Zizmor to enforce secure config (#27304) (@crenshaw-dev)
  • ec10f2e627042e29044b6de5f550f6bacf19708e: feat(cli): optionally exclude status field when using argocd admin export command (#29219) (@nitishfy)
  • 5c3637def4bef8daf16311877d9bc6f98f39f4ec: feat(controller): allow metrics label/condition flags via argocd-cmd-params-cm (#28287) (@edgrz)
  • d94bcb1215c15bbe12835b4653e7c58f42b9241f: feat(dex): Configure TLS Minversion for Dex web (#28712) (@akhilnittala)
  • 465d43b2455fa60c45c02041b553054921934e3d: feat(dex): Making Dex storage type and config configurable from argocd-cm configmap (#28624) (@akhilnittala)
  • 2e2f4e450d57bafa249aaa330d61901f76d424df: feat(health): Implement kyverno health checks (#27354) (@sandert-k8s)
  • 034ab6150952f23071d452f0f6fc0b400124d7e1: feat(health): add built-in health check for TLSRoute (#26596) (@dnfwlq8054)
  • 49aa0eab6d876ba8a69b198e8319495c9931dcfb: feat(health): add health check for AWS ACK resources (#29016) (@philljie)
  • e1145c626c7dee9ba7e437447bc2b3319e042f3f: feat(health): add health check for CloudNativePG Backup (#28468) (@yugstar)
  • 643de0bcff5a48076ce582d8b096a3f5fc1402ff: feat(health): add health check for CloudNativePG Database CRD (#29511) (@Matthiator)
  • ff00ee7d69ffc3d85b175bf37bbc40c7e814d183: feat(health): add health check for Kro resources (#28743) (@philljie)
  • 3825b96ac9ce29b500f8895e47fd44fa26901a74: feat(health): add health check for MedusaBackupJob (issue #28009) (#28008) (@mgross2)
  • 309594ba94218770caa0e922530962b915741b0f: feat(health): add health check for MedusaTask (issue #28007) (#28006) (@mgross2)
  • 6858a80b2af7fde484986ea4bc282c85a489d1fd: feat(health): add health check for Prometheus Operator Alertmanager (#28446) (@yugstar)
  • 2338867cea9ca0390ae5ad33a9b045f72a797f73: feat(health): add health check for Prometheus Operator ThanosRuler (#28463) (@yugstar)
  • 831d77b52c809dec1ae8b7107ccb264825402d7d: feat(health): add health check for cert-manager CertificateRequest (#28465) (@yugstar)
  • dec470a0ab16b7c6a97fe4eb58f9ae430eb0a04f: feat(health): add health check for cert-manager trust-manager Bundle (#28615) (@yugstar)
  • fdf6751b85a04b0b60a23ec0bcd5641c814b09ec: feat(health): add health check for flink.apache.org/FlinkSessionJob (#26626) (@sivchari)
  • 21ac508ef6aaae8238710688fbf26e0c20d2b9d7: feat(health): add health checks for Tekton PipelineRun and TaskRun (#28467) (@yugstar)
  • 180061c9b2cd879b966f60a46e09a83001acc4d8: feat(health): add health checks for Velero Backup, Restore, and Schedule (#28464) (@yugstar)
  • 57088014f10c71331ce6719f1c85d778ccfd5b14: feat(health): add health checks for cert-manager ACME Order and Challenge (#28466) (@yugstar)
  • 291bfab82175b7580165a7a11be282151eac0ad8: feat(health): enable a Pipeline labeled 'recyclable-expired' to be deleted (#28532) (@juliev0)
  • 463f39afe5d91882e51c345fe5bce6ead40adeae: feat(health): support ListenerSet.gateway.networking.k8s.io (#28388) (@root30)
  • ffe66fff46708bbbe4183b13f3d2cde657664c4b: feat(health): support custom deletion messages (#27595) (#27596) (@crenshaw-dev)
  • 5e8ed632babda75965940a0f175010bb974b50b7: feat(health): support various policies _.microgateway.airlock.com (#28268) (@root30)
  • 961bd434659679dd9d80e8a4d83acb71dfcec2cd: feat(hydrator): add metrics to app info (#29512) (#29514) (@crenshaw-dev)
  • 2d71dc6b6e4e1ddda65f950bb3f538e04ca7c76e: feat(hydrator): sign hydrated commits (Alpha) (#28239) (#28271) (@mladjan-gadzic)
  • c2df91b70ff69c24b1b5fc457e384fafab573544: feat(impersonation): allow to disable strict enforcement (#27084) (#27573) (@agaudreault)
  • e2b719ad65d7b09002e0b17b8f1bdf8640c6e7e8: feat(otel): add spans with configurable sampling (#28396) (@blakepettersson)
  • b2e6d1d929cdca79f774075bfaef9f738f1d1524: feat(perf): configurable serialization and compression for cached manifests (#26897) (#28600) (@adityaraj178)
  • e5eb504a3a2b8ad3013dfc6b9962c2a071a4772d: feat(perf): count apps per cluster in a single pass (#29570) (@rumstead)
  • 4c36558382aad92ccdc8129f7045db6f84807950: feat(perf): drop two redundant application copies from the refresh path (#29581) (@rumstead)
  • 37273e31438a571e337058efb6e3fbbe1b28044b: feat(perf): partial json unmarshalling (#29378) (@blakepettersson)
  • 0f901d1e2d9f9e9da3e52ddde9d0c97542aa6a91: feat(perf): resolve the destination server without copying the cluster (#29573) (@rumstead)
  • 0c2545d51db30d8ce5e80a19883f4e8b65bf2947: feat(perf): reuse matrix child params when the generator is unchanged (#29582) (@rumstead)
  • 54a740e1048b80eb3f4856e2cdc25c9bae51df94: feat(resource_customizations): support ignored status for victoriametrics healthcheck (#29351) (@AndrewChubatiuk)
  • 4abcbcf1a904e2ec6ba3310f22d5763b3e4bc772: feat(server): Add support for redirect to selected Dex connector (Alpha) (#24221) (@antonu17)
  • e4470c5ff3cd0a4b948714c3f3c19731d26be05b: feat(server): add configHash field to Cluster (#25311) (#27657) (@matmil-dev)
  • fc848eb1b454870ebab17d1092c44ae6017b3991: feat(server): set X-Robots-Tag to prevent indexing of the UI (#28359) (@yugstar)
  • 0141bf077dea55a15437401e7a61ab07fd2f9ad3: feat(tls): Make TLS Curve prefereneces configurable while setting TLS options for repo-server and server. (#28846) (@akhilnittala)
  • ba47c6b6b0015a9939cd630db444a1e9aa1f957f: feat(ui): Implement virtual scrolling for Apps list/tiles view when all is selected (#29542) (@aali309)
  • bf984eaa6c17dc1d832bbbfd44760cd1e82ada06: feat(ui): Lazy loading (#29087) (@jwinters01)
  • ac0119467ed8bcccf960fffdbe2603f9c6b95efb: feat(ui): add regex search toggle to application(sets) list (#27857) (#27889) (@rickbrouwer)
  • 807320130714a5939242a47f32e48e28a97a02fa: feat(ui): add resources explorer view (#28098) (@agaudreault)
  • 5b4b5def23bce4e7a0d26478ba1674361aab12b1: feat(ui): add search bar and pagination to settings pages (#28305) (@agaudreault)
  • e2a605e0d0a1f2c154c4f2215f8c66a02beba602: feat(ui): add server-side name filter to applications list and watch (#29106) (#29242) (@rickbrouwer)
  • f495ca51ee8f5d725c3ea38c4b7d1a8c227b5f29: feat(ui): advanced settings view (#28383) (@agaudreault)
  • 4fa944edff93a4116eee008e6b018057d4da6965: feat(ui): enable React Compiler in the build (@jwinters01)
  • 9cf8d7c125ac534aa58c1ee089fb48dbe80cd1d4: feat(ui): sidebar anchors (#28527) (@blakepettersson)
  • 91f7adcbcfecfdeb21e87678ccdb1bc1ae15172a: feat(ui): use anchors instead of divs in app/appset tiles and tablerows (#28005) (@blakepettersson)
  • 73bf020633ecd20cd4d96ec9af504b8aab4c98aa: feat(webhook): Add manifest-generate-paths annotation support for BitBucket Server (#27552) (@adityaraj178)
  • ca3139e842d84130ec9ed39bdfaa57ee3998bd1d: feat(webhook): add webhook support for harbor (#27810) (#27884) (@adityaraj178)
  • 7bdadbf693502e8ac5cdfda281e2972eaa2a04da: feat(webhooks): add webhook support for DockerHub (#28022) (@nitishfy)
  • 79b0815beb400ed0ec9c32e36ba7360d4e9b98f4: feat: Add deprecation warning when using --signature-keys (#28941) (@kuci-JK)
  • b5d698a00a2797cbadb8c6d7769b0161daea0f18: feat: Add health check for pulumi.com/Stack (#28534) (@guineveresaenger)
  • 0703fcacf7c7411ffbc3fabf511b7eadc5ec3927: feat: Add health check resource customizations for Envoy Gateway Extension CRDs (#27291) (@obliadp)
  • 34427a68b08f46f0bd43846213a2aaf24452cbd6: feat: Add reporting component to events list (#25684) (#27678) (@Suven-p)
  • 816fcd02cf47cdfaebd93df9bd9d9dac332ff7ab: feat: Allow pod healthcheck to ignore restart policy via annotation (#15317) (Alpha) (#28249) (@jskrill)
  • 48f94615f072046d6621287e0b5c86c07efafed9: feat: Default to SSD with SSA and remove SMD (#29103) (@pjiang-dev)
  • 35238e3472a27604de22939d217bdf98c3ca9b0b: feat: Replace SIGNATURE-KEYS with SOURCE-INTEGRITY in proj list (#28920) (@kuci-JK)
  • 7a80e4ca9272889d9c452cedca7fe459b06bc127: feat: accept repository-style Azure keys in repo-creds (#29414) (#29415) (@SHINMH)
  • 1828831237e85645081cb4483061de4f1687ce4f: feat: add tpl function to ApplicationSet go-templating (#16302) (#26614) (@twobiers)
  • 58d427f5391887092d1ff36c61157a865fadea8d: feat: add a button to clear logs in the pod logs viewer (#27149) (@gcadoret)
  • eb15eb4a23c8820c35a45756ff3a28bd77b3a0c6: feat: add bundled health check for KServe LLMInferenceService (#29599) (#29620) (@sarfarazgit)
  • dcdf8e4026450611d23077271705a44a9f21d10b: feat: add clear all button to ApplicationSet filters (#28593) (@choejwoo)
  • 619c642457581e5929b8628676a7c4517e358c87: feat: add configurable SSO login button text via ui.loginButtonText (#28254) (@NotKiwy)
  • bcb771e29326321b7be0c4bfe2d2a7c742ac7955: feat: add oci generator for applicationsets (#26121) (@robinlieb)
  • 68b8af21e358fa01ea42ba34aa26ab3bd854c4ab: feat: add option to disable Swagger UI endpoint (#28717) (@smahadik-27)
  • 79e1229469403a4e9cbab5043f9128948711a330: feat: add which resources caused the app health to change (#28455) (@agaudreault)
  • e8e5ba20f7a2449a254cc2a380c293099159da38: feat: adds a server-proxy-url flag in cluster add command (#28134) (@ppapapetrou76)
  • bcf18220b76d55a00599da0b8993276c2a419f72: feat: allow optionally setting a prefix for redis keys (closes #12978) (#26169) (@healthy-pod)
  • 7cfc6cfd2e7b5de1b9e29ee497a07135405047d2: feat: allow to create Jobs from CronJobs with OwnerReferencesPermissionEnforcement admission (#26009) (@sathieu)
  • 0984033236c695ee20ae344c402fa0d30e8a30fd: feat: support REDIS_SENTINEL and REDIS_SENTINELMASTER env vars (#28391) (@suii2210)
  • 127dbe7bcd94f3f6883eae1f2f3465763e5a5282: feat: support filtering out managed resources using label selector (#29423) (@alexmt)
  • 9e9c2f1e751242cb3c26aaa9cc5d4cbe6426139e: feat: support ignore-differences annotation on resources (#29616) (@ranakan19)
  • 7d05a395eb4149c9c8d41cad3f27a20c3d6367fd: feat: support separate RBAC permission for application rollback (#28924) (@ppapapetrou76)
Bug fixes
  • 545bcb5eeba8240ffa47299ee9ace8bb54c61dc8: fix(SyncWindow): rename SyncWindow to InlineSyncWindow (#29152) (@adityaraj178)
  • dcf03494eff98102a44ea10f1a66d80b8644b948: fix(UI): display sync option dropdowns on separate lines (#28438) (@adityaraj178)
  • 20ad5f9922600aaa54b82daa4cd7a5e3f63a709f: fix(application): use server-side timeout query parameter via transport wrapper (#28828) (#28977) (@luwangVMW)
  • 9bb331250c0d3f8d47d337208866afca93f86b73: fix(appset): don't release finalizer while children still terminate (#28999) (@blakepettersson)
  • 777f9132b73d6f9b93798f6c4900556c36b1cf7f: fix(appset): fail reverse deletion when a stale cache entry cannot be evicted (#29042) (#29140) (@himeshp)
  • fea95e66c423f71c393f1303dc6a2a85a858b5d5: fix(appset): fall back to create when patch returns NotFound (#17312) (#28645) (@rickbrouwer)
  • a822683efd4a73360b5643b6a2d53d2f2326ee7e: fix(appset): restore ignoreApplicationDifferences after normalization (#29070) (@pjiang-dev)
  • 3be29876ba77072cfbf4585b2d8a28b2d0912a1a: fix(appset): stop progressive sync reconciling in a tight loop (#27577) (#29044) (@himeshp)
  • 4891d4f4745ae87b9aebd2577d0fe5a3433b8aab: fix(appset): throw error when generated apps have empty name (#28833) (@nitishfy)
  • 29faea2da97274e1eba16bd87d026eb50f942880: fix(appset): verify terminating Applications against the API server (#29042) (#29043) (@himeshp)
  • 81cd93e553ce915075599a32335032322c44bc23: fix(chore): bump argo-ui for React 19 toast compatibility (#28874) (@choejwoo)
  • 73661b801935213221948c167acd943e1eb20f6e: fix(ci): exclude generated workflow from dependabot (#28774) (@crenshaw-dev)
  • 760229084538b77a5b269bf2449a7d2f19087dea: fix(ci): expand image tag in staging deploy commit message (#28773) (@crenshaw-dev)
  • 955378d6e015d48ee58357532b86545c50bd716a: fix(ci): explicitly check out base repo and default branch for cherry-pick job (#28413) (@blakepettersson)
  • 82682852c7f0684b57052e8d9447fd0c733983e9: fix(ci): fix CI breakage: remove dependabot's changes to an agentic workflow compiled file (#28772) (@dudinea)
  • 1af3199ee504a86ddf1a6ed30ad11c392b310b75: fix(ci): fix readthedocs build by removing an invalid link (#28449) (#28450) (@dudinea)
  • 541db75ef88063896ee5ea5d3628549319a25af1: fix(ci): gitkeep so go builds work (#28461) (@crenshaw-dev)
  • bef2051b11a07e26981ea13dc1d48ba749610b76: fix(ci): regenerate manifests in Renovate helm post-upgrade tasks (#29297) (@crenshaw-dev)
  • 2df94aebe8710797e14ceee0e8141d98efcc40c0: fix(ci): remove unneeded and misnamed ui/dist/app/gitkeep (#28447) (@dudinea)
  • ebcbc95aaabc0b884fee860fef5082d761274db7: fix(ci): strip v prefix for helm and git-lfs renovate checksum tasks (#29287) (@crenshaw-dev)
  • bb33bb0d1e724bac9e6964af98c76cebe5ab6be9: fix(cli): skip stale destinations in cluster stats (#21808) (#28786) (@AkashKumar7902)
  • 5f4e24ec353399da81664ea1e04e9c758de21579: fix(controller): correct metrics flag help names. (#28358) (@siddiksawani)
  • 28334d185e594be8b4b6bae8bbe428316aeb078c: fix(controller): dropping refresh requests during reconcile (#28603) (#28414) (@dudinea)
  • cb99c80a553aa3eb25b38a8216ddac0b16aa3013: fix(controller): reuse server-side diff result when masking Secret data (#27858) (@1ovsss)
  • f8c252b09b2c0213d1635d4f8417dd2d37f66768: fix(controller): show retry wait time in unambiguous format (#29534) (@nitishfy)
  • b9e9d4117c89a97c84afc98022d1ccef867637c5: fix(controller): treat timeout.reconciliation=0 as disabled soft expiry (#27683) (@aali309)
  • f4adccd118f0ee0aa8a0149f94db56cc14f9cacd: fix(controller): use diff cache when timeout.reconciliation is disabled (#29073) (@aali309)
  • 360aa9ba318d11a3c8805561d5fe7b7b771871a8: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (#28819) (@pujitha24)
  • 3fbe407789117445d088c41f867337591db33173: fix(doc): correct cluster generator example comments (#29196) (@aminerachyd)
  • e2d36692fb8106cdf496d4756f476fa72da5ac0e: fix(docs): correct broken documentation links (#29572) (@yashrajshuklaaa)
  • 7cec612777e9d5fb5c1b7966faf1bf0fc71df321: fix(docs): link version banner to stable equivalent page (#27054) (@SkyShineTH)
  • 3c5af0d9dc49a1c8f55fa2a32cc75eeacbea7d8b: fix(headless): enable SyncWithReplaceAllowed by default for in-process server (#27643) (@SAY-5)
  • fd04feb4b2b795fcabc67ceb41bffd121c37ad0a: fix(health): AWSManagedControlPlane reports Healthy while EKS control plane is updating (#28936) (#28937) (@moko-poi)
  • e238e1a4e6aec5285cdfd1b81c6f61dc2c5dd87d: fix(health): Crossplane MRs should report Progressing (not Healthy) whilst provisioning (#29381) (#29382) (@kjothen)
  • 381b41866746fe7c5161091ddfa40739dbe2142c: fix(health): PromotionStrategy and ChangeTransferPolicy Healthy, not Progressing (#28434) (@crenshaw-dev)
  • ae1fc9969313e39242663ed6a1b0d6f408456dfc: fix(health): ResourceBinding health check for dependency-propagated bindings (#28299) (@pncloud)
  • 785005d9096eecd0ce2e2f1af192cb5bf2600324: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (#29664) (@daixtrose)
  • a1e358a57f52d14696d77cdc10eaee61a48c9024: fix(health): report suspended FlinkDeployment as healthy (#26818) (#28995) (@SaiPisey2)
  • 7cf440730872497c3b32c1c802690a1784e58979: fix(health): surface the Suspended condition message for suspended Jobs (#28738) (@semx)
  • fd09092b7d46ec7bb36b663a32c9d888cfb5e5d6: fix(health): treat nil return from Lua health status script as n/a instead of unknown (#28269) (@snorwin)
  • b48e31cfbbbbd1c8233b58620873770757aed3ff: fix(helm): pass registry passwords through stdin (#17821) (#28795) (@AkashKumar7902)
  • 65feaf50238bf8220fbacfc3576ecf12f0a67712: fix(hydrator): retry notes push on cannot lock ref errors (#28469) (@Churi12)
  • 906ca1166d68e024391012c8605bbebe377c394a: fix(metrics): expose application operation phase in argocd_app_info (#28719) (@vishnu97770)
  • aeda334c73e682fa2ea0ea0b0a93766e9ebf42a8: fix(progressivesync): check if error == notfound (#28663) (@blakepettersson)
  • cd44f2784d2222cd0cfb0de1d54f005bcc1b6a53: fix(redis): incorrect fail metrics on RENAME cache miss (#29037) (@agaudreault)
  • c7457d0668d321444560e1c0db56278c585c417c: fix(reposerver): honor depth of referenced source instead of primary source (#28339) (@alexandresavicki)
  • c73a59ad73e4e4b15f28ec3bdeeec5516038daad: fix(repository): clean repository on revision change (#28771) (@emil-ep)
  • 2f7eee24a6c5eb08b9c8f4bc62dbf1ea45ec6391: fix(repository): resolve untyped helm source type in UpdateRevisionForPaths (#28904) (@Churi12)
  • b77bdaa2c76df9da83b26bf484c6deaf109263f5: fix(repository): restore Normalize in UpdateRevisionForPaths to unbreak master (#28979) (@Churi12)
  • c71119fe756e12550670a78edf2eae08b935aef0: fix(revert): auto-sync skipped when newer commit arrives during sync (#28692) (@blakepettersson)
  • a37f1f1ad303dae728381260dfe35edeb7d55ab3: fix(server): prevent SSD CLI secret mask spoofing (#29089) (@pjiang-dev)
  • 994e271bcc3c591540bbe778bf09df303dcbf5f7: fix(ssd): hide secret in last-applied-configuration annotation (#28989) (@pjiang-dev)
  • a683bdec6afe94c9ed88b6c7744d909407e12ec7: fix(sync): add state information for sync operation (#28758) (@agaudreault)
  • 9b40474c009cc0a3596da7180501b7f259b90700: fix(sync): correctly set operationState values on retry (#26530) (#28778) (@agaudreault)
  • ba8600cb76922a8b252052d9a127a3b184446f44: fix(sync): do not pass --force to server-side apply (#29624) (#29626) (@KR-Ravindra)
  • 5ee2ae0cf42cc5501eb957e3648f66beb0e3008c: fix(sync): reduce unnecessary sync operation caused by refreshes (#28619) (@agaudreault)
  • 5da9053d0ebcccf2a5858bd6578b9a5a8ec52255: fix(ui): Fix Hydrate-To revision name in App details (#27134) (@olivergondza)
  • a1c22f1086166c9023e15bc0929b2a4983ee91be: fix(ui): add ResizeObserver to Monaco editor to fix collapsed rendering (#28810) (@choejwoo)
  • 2fadff2054bbecf1f6283ecbeefdcf2fc3d1ef44: fix(ui): clarify scoped repository copy (#22793) (#29177) (@SHINMH)
  • 1214aeda6bb23a02bf91427c587112899f3a73ea: fix(ui): enhance Bitbucket Server URL handling in ui for repo and revision links (#2

v3.5.3

Sep 14, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.3/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.3/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • c198be7e7a00f6e643180c0f9b762f768fefcbb1: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (cherry-pick #29664 for 3.5) (#29665) (@argo-cd-cherry-pick-bot[bot])
  • 4b3f69d204d25aeaf9056bc37c3e4d44f198570c: fix(health): report suspended FlinkDeployment as healthy (#26818) (cherry-pick #28995 for 3.5) (#29525) (@argo-cd-cherry-pick-bot[bot])
  • dd2cb1aaf12ef19a2bab816fbaecced6422cad7c: fix(repository): clean repository on revision change (cherry-pick #28771 for 3.5) (#29486) (@argo-cd-cherry-pick-bot[bot])
  • 70b399c5a8335cd3abb0bf132d63129733a5e3a0: fix(resource_customizations): Crossplane MRs should report Progressing (not Healthy) whilst provisioning [ISSUE: #29381] (cherry-pick #29382 for 3.5) (#29520) (@argo-cd-cherry-pick-bot[bot])
  • be8b3873521671e3f9418c6e3019f12a472ac3c1: fix(sync): correctly set operationState values on retry (#26530) (cherry-pick #28778 for 3.5) (#29431) (@omkar619-dev)
  • a5e5992f62561d112a6d6a715e6631e3b6817671: fix(ui): guard SSO redirect to stop 401 retry loop (cherry-pick #28807 for 3.5) (#29631) (@argo-cd-cherry-pick-bot[bot])
  • 0b0890e0c79d2e2c7f8bf33736cde2772024e2b3: fix(ui): use hydrateTo branch name when set (cherry-pick #29562 for 3.5) (#29564) (@crenshaw-dev)
  • 18f0566fb550b1d10d9fb55a72fa887a530eca42: fix: GRPCRoute health check ignores stale observedGeneration conditions (#28086) (cherry-pick #28087 for 3.5) (#29517) (@argo-cd-cherry-pick-bot[bot])
  • 4d653a67174ecacd3a7d17ef5f1c923a48304bd6: fix: handle GrafanaFolder negative-polarity condition (#29395) (cherry-pick #29397 for 3.5) (#29524) (@argo-cd-cherry-pick-bot[bot])
  • ec585202b451045155203736eaa6bca145b19935: fix: recover AuthReconcile visitor panics (cherry-pick #29440 for 3.5) (#29531) (@Karthik-Chowdary)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.2...v3.5.3

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.4.9

Sep 14, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.9/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.9/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • b938a5e7238c5993534156acdd39953d0aab2bc0: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (cherry-pick #29664 for 3.4) (#29666) (@argo-cd-cherry-pick-bot[bot])
  • 8d84b9380186ef6e1b694c718128ddb4b4cbb5ee: fix(health): report suspended FlinkDeployment as healthy (#26818) (cherry-pick #28995 for 3.4) (#29527) (@argo-cd-cherry-pick-bot[bot])
  • bfd48bd87729d1675509d89cf9eeb41d83d6a967: fix(repository): clean repository on revision change (cherry-pick #28771 for 3.4) (#29485) (@argo-cd-cherry-pick-bot[bot])
  • 4e0f6b78ce57547415eaac042a35a29f7fa0345c: fix(resource_customizations): Crossplane MRs should report Progressing (not Healthy) whilst provisioning [ISSUE: #29381] (cherry-pick #29382 for 3.4) (#29521) (@argo-cd-cherry-pick-bot[bot])
  • 182c837b67b7176e03342b19e0a7d23a4da347af: fix(sync): correctly set operationState values on retry (#26530) (cherry-pick #28778 for 3.4) (#29432) (@omkar619-dev)
  • ae7133151cd1ad803455a18a810c7a091de09b69: fix(ui): guard SSO redirect to stop 401 retry loop (cherry-pick #28807 for 3.4) (#29632) (@argo-cd-cherry-pick-bot[bot])
  • 38b5adf870e5aa0521a0a2e2638af11cf087a518: fix(ui): use hydrateTo branch name when set (cherry-pick #29562 for 3.4) (#29566) (@crenshaw-dev)
  • fb9431d44e8f61fe0b156a1abb9289b9d85dbe2c: fix: GRPCRoute health check ignores stale observedGeneration conditions (#28086) (cherry-pick #28087 for 3.4) (#29518) (@argo-cd-cherry-pick-bot[bot])
  • 51edefdfb252547d408b70da03fceb78a3e0e387: fix: handle GrafanaFolder negative-polarity condition (#29395) (cherry-pick #29397 for 3.4) (#29523) (@argo-cd-cherry-pick-bot[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.8...v3.4.9

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.5.2

Aug 27, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.2/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.2/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • f1f109cc20895275ebae2dc62e51cba6c788586b: fix(appset): restore ignoreApplicationDifferences after normalization (cherry-pick #29070 for 3.5) (#29195) (@argo-cd-cherry-pick-bot[bot])
  • a45dd38594f6f30bcc6c743e6f11080187cc84a1: fix(repository): resolve untyped helm source type in UpdateRevisionForPaths (cherry-pick #28904 for 3.5) (#29399) (@argo-cd-cherry-pick-bot[bot])
  • 417c675b17207730f3b89ed579132267c9af4892: fix(revert): auto-sync skipped when newer commit arrives during sync (cherry-pick #28692 for 3.5) (#29224) (@rumstead)
  • 961ee40cc32717bad323629284085b9f2cd7173f: fix(ui): remove kind filter from appset page (#29310) (#29311) (cherry-pick 3.5) (#29314) (@crenshaw-dev)
  • cc1f3eef40dfee35842cc5a4c27a80b5f5dbe82e: fix(ui): show operation state on applications list page (cherry-pick release-3.5) (#29344) (@antonu17)
  • 5accee3440f1a140de32071a035b783d653ce452: fix: don't degrade Cluster API Cluster health while Ready is False during provisioning (cherry-pick #29237 for 3.5) (#29273) (@argo-cd-cherry-pick-bot[bot])
  • 4d99c524afda80d091dff81e8745eb3365285874: fix: recover from kubectl panic in AuthReconcile when SA is forbidden (cherry-pick #28669 for 3.5) (#29294) (@alexymantha)
Dependency updates
  • 8b9e270fa2cefb4eb370609b38606bf1a3ae410e: chore(deps): update dependency dexidp/dex to v2.45.1 (#29334) (@nitishfy)
Other work
  • e258ee23c3e52266d407572f4bcdfe7d9ed36cb5: chore: bump version to 3.5.2 on release-3.5 branch (#29404) (@github-actions[bot])
  • a9d94d68c8a5bee4e1708f6640e7922b91736fec: fix(notification-controller): deep-copy before mutating object from a shared cache (cherry-pick #29350 for 3.5) (#29354) (@argo-cd-cherry-pick-bot[bot])
  • cc1d7a2601ce87695808a2632687975a84900a54: fix(notification-controller): read appprojects from informer cache (#28815) (cherry-pick release-3.5) (#29345) (@antonu17)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.1...v3.5.2

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.4.8

Aug 27, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.8/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.8/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 90f81d5bc27491a97fb6d0ab0dc284a69ed14a08: fix(revert): auto-sync skipped when newer commit arrives during sync (cherry-pick #28692 for 3.4) (#29225) (@rumstead)
  • 924ab35b93689ddba28731bdaa45a189ac653ddc: fix: don't degrade Cluster API Cluster health while Ready is False during provisioning (cherry-pick #29237 for 3.4) (#29274) (@argo-cd-cherry-pick-bot[bot])
Dependency updates
  • e4de80d7eee32f93416d9722719d4b8b1c1d47bf: chore(deps): bump DOMPurify to 3.4.7 for CVE-2026-49978 (#29222) (@aali309)
  • 24754268593ae81a052bec378b8e967af787987f: chore(deps): bump brace-expansion to 2.1.4, 1.1.18 in /ui for fixing CVE-2026-14257 and CVE-2026-69152 (release-3.4) (#29379) (@nmirasch)
  • e5bee2c2bbbff7b0c65b213addaf84e30ad66f94: chore(deps): bump js-yaml to fix CVE-2026-59869 (#28946) (@aali309)
Other work
  • 609fa82ba26de2369c7b5138279f06a2af1d13a5: chore: bump version to 3.4.8 on release-3.4 branch (#29405) (@github-actions[bot])
  • 9c771f6f7cbd4448fef1a11fb03be7579c1e2fd3: fix(notification-controller): deep-copy before mutating object from a shared cache (cherry-pick #29350 for 3.4) (#29353) (@argo-cd-cherry-pick-bot[bot])
  • bad3c481d2ceeaff1ad0e48b6c7c9fe23f77f118: fix(notification-controller): read appprojects from informer cache (#28815) (cherry-pick release-3.4) (#29346) (@antonu17)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.7...v3.4.8

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.5.1

Aug 12, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.1/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.1/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 33f3bc59faeec96204cda3a5ae211be17d15f1ac: fix(appset): stop progressive sync reconciling in a tight loop (#27577) (#29139) (@himeshp)
  • d358e75b3539c3fc43eb2372317bde7a0d01c55f: fix(appset): verify terminating Applications against the API server (#29042) (#29138) (@himeshp)
  • ecf37373a9d3a72b259a73abfee7ce27226b960a: fix(controller): cherry-pick treat timeout.reconciliation=0 as disabled soft expiry (#27683) (#29007) (@aali309)
  • 978fa65006565baaaf35894918fd661d610f5953: fix(controller): reuse server-side diff result when masking Secret data (#27858) (#29074) (@1ovsss)
  • f399c84f85fc4e3a19ac1e8314ff111493d26fee: fix(controller): use diff cache when timeout.reconciliation is disabled (cherry-pick #29073 for 3.5) (#29158) (@argo-cd-cherry-pick-bot[bot])
  • 960bed7f2efcdc8b43fe392dd6d17cf95507c9f2: fix(server): prevent SSD CLI secret mask spoofing (cherry-pick #29089 for 3.5) (#29130) (@argo-cd-cherry-pick-bot[bot])
  • 9f360f4953a1dc0f3474aa9c482d72366863ea33: fix(ssd): hide secret in last-applied-configuration annotation (#28989) (#29052) (@pjiang-dev)
Other work
  • 109ca7ca71139e514114499d294a492e7910a965: chore: bump version to 3.5.1 on release-3.5 branch (#29165) (@github-actions[bot])
  • b44fbbc2e040e303c18a69182fd5dbe2c36cfdf9: fix(manifest-generate-paths): Consistent gen manifest cache key (#28074 and #29037) (#29049) (@agaudreault)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.0...v3.5.1

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.4.7

Aug 12, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.7/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.7/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • cbd768784b51cf3ac15143d8ab3ee8e1fa28bfd1: fix(appset): progressive sync fixes (3.4 backports of #29042 and #27577) (#29141) (@himeshp)
  • 0781a1a9f1c5cf4d69e2dd8e93d65abce7386adc: fix(controller): reuse server-side diff result when masking Secret data (#27858) (#29075) (@1ovsss)
  • a09c39ca9c18eb1f7f7ca79909ba5d2ec013d1b7: fix(server): prevent SSD CLI secret mask spoofing (cherry-pick #29089 for 3.4) (#29131) (@argo-cd-cherry-pick-bot[bot])
  • 8afda0dc851b5012272951b2036a5d6caae5d7ec: fix(ssd): hide secret in last-applied-configuration annotation (#28989) (#29053) (@pjiang-dev)
Dependency updates
  • e0aea006fb6acd5a69740cbd806769e501933ded: chore(deps): bump fast-xml-parser from 4.5.3 to 4.5.6 in /ui - 3.4 (#27342) (@keithchong)
Other work
  • 7b6113c14c8186e126046131dfbe5103a9f680f4: chore: bump version to 3.4.7 on release-3.4 branch (#29161) (@github-actions[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.6...v3.4.7

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.3.14

Aug 12, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.14/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.14/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 7242ed2d3cd3a5bb106a1922834244977de83b9f: fix(controller): reuse server-side diff result when masking Secret data (#27858) (#29076) (@1ovsss)
  • d93267f05a6c59cc04f472e3bbe1dc0da1d7cf3b: fix(server): prevent SSD CLI secret mask spoofing (#29089) (#29137) (@pjiang-dev)
  • 4e181b9ba61f1ab7aa85ac890328e4b4938195c9: fix(ssd): hide secret in last-applied-configuration annotation (#28989) (#29054) (@pjiang-dev)
  • 80f08f9de360a22abbb314a5b6b18a71b9a4140c: fix: register pprof endpoints in repo-server using the params config map (cherry-pick #26237 for 3.3) (#29032) (@gdsoumya)
Dependency updates
  • cf38a82132a2275c6229368cdfd8872e3b0d33d6: chore(deps): bump DOMPurify to 3.4.7 for CVE-2026-49978 (#28969) (@aali309)
  • d3f7e8c0b5a40611fe6751b65a475be7b26e4726: chore(deps): bump brace-expansion to 2.1.4, 1.1.18 in /ui for fixing CVE-2026-69152 (release-3.3) (#29149) (@dkarpele)
Other work
  • a0a99e187cb6126ef0f3be82d90705513d8f6f3e: chore: bump version to 3.3.14 on release-3.3 branch (#29159) (@github-actions[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.3.13...v3.3.14

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.5.0

Aug 4, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Features
  • be19446a015a33ba33bb91a0029b984d394ae1a7: feat(Jitter): Add Configurable Jitter for Webhook-Triggered application Refreshes (#25433) (@adityaraj178)
  • 5b3073986f50b6775ea6ddef8d83aff05284eece: feat(appset): add concurrency when managing applications (#26642) (@rumstead)
  • 29fd8db39ac979e4dcf2611fb9716ee14a632454: feat(appset): filtering repos by archived status #20736 (#21505) (@prune998)
  • 57942cef9091e732b1ab6c158201f1d9728044db: feat(cli): Add support for Source Integrity configuration (#26997) (@olivergondza)
  • 3cc6ba749640dfd3a4d9ed4d73ec44c29c38e7df: feat(cli): add --app-namespace flag to missing argocd app subcommands (#27942) (@Mangaal)
  • 0e729cce3474818bf19e8deb6ff015fffe3fed7d: feat(cli): add appset-namespace for appset command (#27022) (@Mangaal)
  • 744983be594fbf0bc651b28d639235b758a6c7a9: feat(health): Add healthcheck for gardener "Shoot" resources (#25750) (@Sven1410)
  • 6cc786d056d77c6d0f24a384c1d0809ef6a87258: feat(health): add GatewayClass health check (#26591) (@dnfwlq8054)
  • eabd4d64041dad10b3e1d500e0f13f1f66ce3394: feat(health): add pause and unpause actions to psmdb resource (#27616) (@KyriosGN0)
  • daadf868db028bacde40e008524ba89d49b0dc8e: feat(health): additional promoter.argoproj.io health checks (#27170) (@crenshaw-dev)
  • 4b69a7f468850bee3897e660ef0a4cff09b913d9: feat(health): finalizer messages for Promoter checks (#27478) (@crenshaw-dev)
  • 289a4c01dbf67aa520a3ae973da74080689650a3: feat(health): support BackendTLSPolicy.gateway.networking.k8s.io (#27385) (@snorwin)
  • 4cdc650a581cc92d393b50daf396c90de12d0e09: feat(helm): support wildcard glob patterns for valueFiles (#26768) (@nitishfy)
  • f7a7deb8d7dcb9c95957a425f26a4bbf23be04ad: feat(hydrator): dynamically manage README template from argocd-cm ConfigMap [updated] (#19067) (#24309) (@gyu-young-park)
  • 86936e24c5f7c739d89bc8692d286355ae749086: feat(hydrator): make manifest hydration queue concurrency configurable (#27926) (#27948) (@GuruduGanesh)
  • 2308e17da20423c82525e59b1a974673594be2fe: feat(hydrator): opt-in source integrity verification for dry sources (Alpha) (#19302) (#28084) (@mladjan-gadzic)
  • bf1591de63e39b7c3be5f5ba54abe8763de1a48c: feat(hydrator): support syncSource repoURL for separate destination repo (#27011) (@boostrack)
  • 41b6fee59d67b8ba22bba995a7c0bbc44eb2512f: feat(impersonation): allow to disable strict enforcement (#27084) (cherry-pick #27573 for 3.5) (#28595) (@argo-cd-cherry-pick-bot[bot])
  • 0c0140ce3e9fc4e9b1137c898e9304318c14e201: feat(metrics): add parallelism limit repo server (#27911) (@pjiang-dev)
  • 7d2eb7722fba79be7b3745f0ced39e9301a9a407: feat(renovate): clean up config and remove github app (#27738) (@rumstead)
  • 153ec679073278008d6c9f85c4e449e140176382: feat(resource_customizations): add health checks for VictoriaMetrics (#27451) (@megative)
  • 6b84ea938d9cdaba0ac9eca6e55f05db6bc38343: feat(server): drop objects from non-allowed namespaces before they enter the cache. (#28018) (@christianh814)
  • 224b75af210188ef7763c47ac4a9f95a7d3da79e: feat(server): use typed Argo CD EventList for event-listing APIs (#25767) (#26322) (@chansuke)
  • 64a04177beed5e02b52328f93412c4d09b507699: feat(ui): Add AppSet to Application Resource Tree (#26601) (@pjiang-dev)
  • b035a77b815fb117b002757b7c258289228a3a38: feat(ui): ApplicationSet Preview Apps tab in UI (#27799) (@pjiang-dev)
  • 566c1720583acc949c0e7027f337b1c2aed13edb: feat(ui): add GitOps Promoter resource icon (#26894) (@crenshaw-dev)
  • 0dd887435f92a54650949bad3ab611a1b179fe8d: feat(ui): add nauth.io resource icon (#28226) (@choufraise)
  • f16d08ad2d24ba44520c5d4977c93943bab3133e: feat(ui): add repo url as filter in home page (#26670) (#27418) (@adityaraj178)
  • 91e7664f3f87129320bca9808d4ff2c99d7a83fb: feat(ui): per-application notice banner and info icon (#14405) (#27719) (@gdsoumya)
  • 1b405ce2b53fa6c7c586dbcf4e6416f08f4fb1dd: feat(ui): search filter by target revision (#24038) (@choejwoo)
  • 706a0370c2f10d335b703c1eaed9452df413cb1e: feat(ui): support creating multi-source applications in New App panel [CONTINUED..] (#27095) (@aali309)
  • 2fcf10476f80fae05c4a02416bc1b047244b0087: feat(ui): support spec.sourceHydrator.drySource.repoURL (@crenshaw-dev)
  • 74d1fe0a13d34f7e6488c70b0f8f687f476f9be3: feat(ui): use toggle-auto-sync resource action in app details page (#21564) (#27226) (@shiiyan)
  • db7d672f05cca2a525cbcc66cf7d64439f71c086: feat(webhooks): add webhook support for GHCR (#26462) (@nitishfy)
  • 6d92e177b45fcd51bde0dbc169f7f923acc9a79d: feat: Add ProvideClusterInfo and Config fields to ExecProviderConfig (#24282) (#27976) (@mikeshng)
  • 022f9354ff82f70bbd19f2dcc5b86a6de208e9f9: feat: Add basic support for git tag path prefixes (#27290) (@k4r1)
  • aad3422ac44bd9afdefd56406bf25730db11f620: feat: Add suspend/resume actions for MariaDB (#27675) (#27674) (@mgross2)
  • 586430c1a37787e6f431783913dceb45fd30a486: feat: Migrate from Helm 3 to Helm 4 (#28076) (@reggie-k)
  • c61c1dcf3a4fd709080a1f52ddf3e1cc1369e39d: feat: Render Helm ValuesObject as YAML in log output instead of binary (#18342) (#27649) (@subhramit)
  • 9a1973591898d29ddda6b56e3c7839981057d7c9: feat: Support Azure Service Principal authentication for Azure DevOps repositories (#25324) (@allanyung)
  • 97082e82759f46a16389e38745e77b2ba1a94efa: feat: add Gateway API support to network view (#26188) (@tete17)
  • 603c900ab57b394fc7d3839c1db6ce0391d87331: feat: add action to delete recyclable Numaflow pipelines (#25900) (@dpadhiar)
  • de9416137d40bb8974114f76b49948d3144c33fe: feat: add action to restart StrimziPodSet (#27266) (@KyriosGN0)
  • a2b91ce309ec9b0a84c8afcf188c5c04121bda43: feat: add depth option to ui (#26618) (@blakepettersson)
  • 1dc2ad04ffea216957a0a49113943daa52576d6b: feat: add health check for karpenter.sh/NodeClaim (#26876) (@Navneet072300)
  • 611fcb012c7e2cc48c6a9cb906b21f6097a9f9bc: feat: add sync overrun option to sync windows (#25361) (#25510) (@puskunalis)
  • 48f18e29055d01dfacf882c3dcac2d6c2f6f3e0c: feat: add toggle-auto-sync resource action for Application (#21564) (#26477) (@vikasrao23)
  • 2df5f75727d5365ac5018d40b8d3eadc1d51decf: feat: adds mTLS support in repo-server (#26715) (@ppapapetrou76)
  • 4d02fc2f59bd2f0d89f991ac2a769105fcfeca8c: feat: expose Appset UI and fix pie chart summary (#26666) (@pjiang-dev)
  • a889f467ada89ad0d7b24c7e8c2d28b926f375be: feat: make appset proxy-url param a native flag (#27788) (@ppapapetrou76)
  • ad310c2452b5a973dbc698d70b48973687f38e3e: feat: replace error message in webhook handler with metrics (#27215) (@alexmt)
  • 01187d114b072d2a253896a5abc6c9b3f47fc1f2: feat: support Azure AD groups claims overflow via Microsoft Graph API (#27397) (@gravufo)
  • f71239cc2a69614bf2f2e60e4f86ab20a6364ac8: feat: support destinationServiceAccounts in global projects (#23059) (@enneitex)
  • f460a3ca4c09ef90967bafacddb70f55f211f5d0: feat: surface root cause in sync failure message and cache discovery errors (#27750) (@ppapapetrou76)
  • 3eebbcb33b9d1684d967ea91459bd16235cb6e04: feat: use impersonation for server operations (logs, delete, etc) #22996 (#26898) (@alexymantha)
Bug fixes
  • b982144fb8d72cf300315496f89245c6799a25f5: Revert "fix: prevent automatic refreshes from informer resync and status updates" (#27562) (@agaudreault)
  • c5d1c914bbc3373d133de16d49bbc06acac6dfe8: fix(UI): show RollingSync step clearly when labels match no step (#26877) (@aali309)
  • c52bf66380a2dd37855f2ffdf5803f6400d0bd2d: fix(appcontroller): application controller in core mode fails to sync when server.secretkey is missing (#26793) (@anandf)
  • e81969ff50c1d097d69efb8566d912a59be788ba: fix(applicationset): include repo URL in git file generator errors (#28075) (@morning-verlu)
  • e4fe7f6a949632a6267bda50c399eb8c7cf1fdc6: fix(appset): don't release finalizer while children still terminate (cherry-pick #28999 for 3.5) (#29006) (@argo-cd-cherry-pick-bot[bot])
  • 06fae9ddd5798ff1be10c007624174673d31eb1b: fix(appset): fall back to create when patch returns NotFound (#17312) (cherry-pick #28645 for 3.5) (#28716) (@argo-cd-cherry-pick-bot[bot])
  • 45a84dfa38c17483baef283e3fb5f80a13b988cf: fix(ci): add .gitkeep to images dir (#26892) (@blakepettersson)
  • 4c42071c7b98d30b891f0d1722c37edaea62f615: fix(ci): openssf scorecard doesn't allow global vars (#27203) (@crenshaw-dev)
  • 36f4ff7f35ce330dd08f52e2a5f0d12782c83735: fix(ci): pin goreman version used in ci-build.yaml (#27062) (#27061) (@dudinea)
  • 25b30374852bb71f0a2bdadbf8f37f604c2c7980: fix(ci): pnpm sbom generation (#27337) (#27339) (@crenshaw-dev)
  • 99c51dfd2c710f8cea7a1dd522b9b105fc2a7387: fix(ci): renovatebot action uses floating image tag (#27023) (#27024) (@dudinea)
  • fb82b16b2db239960392a86bfa74ac64c89012a1: fix(ci): run yarn install with --frozen-lockfile (#27098) (#27099) (@dudinea)
  • b403f5c177aec17aae2ea674864a38e7c40f77ae: fix(cli): hide unsupported --tls-server-name kubectl REST flag (#27694) (#27711) (@SAY-5)
  • 60b878d0c5c86600a1297e296039bfb18436e017: fix(cli): hide unsupported kubectl REST flags (#25875) (#25977) (@HyejunKoo)
  • 21fe1fbd086a1361056a3eae72b71a45cb8699fd: fix(cli): honor --kube-context when creating core-mode REST config (#12883) (#27661) (@ystkfujii)
  • 52f7b3bed49a89d7599d08706d4b0642f7502689: fix(cli): print clear timeout message when argocd app wait times out (#28274) (@pncloud)
  • f48091a3f0e409c2c9963b56f1a5fbc15f011846: fix(cli): return immediately from 'app wait' when app is already in desired state (#12211) (#27503) (@jheyduk)
  • 6256abf182c2765d814df55791f654ffe84ae710: fix(cli): uses DrySource revision for app diff/manifests with sourceHydrator (#23817) (#24670) (@adityaraj178)
  • c3c12c1cad5dd54a96d3ac216c89e839f80c67d4: fix(commitserver): Static analysis fixes (#27085) (@olivergondza)
  • 5a20f9b966e885c2a69820e9d9bd97a2bab76515: fix(controller): gracefully handle k8s resource size limit for applications (#27802) (@nitishfy)
  • 32f23a446febe4a281db3384b8770816fd719749: fix(controller): reduce secret deepcopies and deserialization (#27049) (@rumstead)
  • 4051511698ebeaf643e33b85c54f3d54c387d9ef: fix(controller): replace removed kubectl PodRequestsAndLimits (#27895) (@mfacenet)
  • 5ec06031ba40b52e090475ad6e24fd097e11aa0e: fix(controller): requeue source hydration on periodic refresh timeout (#27009) (@boostrack)
  • a62624ae60e70e1e16b379dd8fae66dfc67282fd: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (cherry-pick #28819 for 3.5) (#28895) (@argo-cd-cherry-pick-bot[bot])
  • e96063557a0c13d0cbc835cd4381d6607c2e29b2: fix(docs): Fix formatting and clarity about requestedScopes in Keycloak integration docs (#27019) (@todaywasawesome)
  • d449294f0315d1e8029055841630a160540e169b: fix(docs): Fix manifest path in Source Hydrator docs (#27123) (@olivergondza)
  • 2f48cfb56f1332b571f4973ccffa3367f82b560b: fix(docs): revert bogus 3.3-3.4 upgrade guide changes in #26322 (@dudinea)
  • c2044db23830dfa91f4475183dfcae0bef243053: fix(health): PromotionStrategy stuck Progressing after no-op re-hydration (#28124) (#28125) (@crenshaw-dev)
  • 9c67c89f15bafc62f604581bf3292914f1c56efd: fix(health): add missing HPA degraded states for metric failures (#26274) (@rickbrouwer)
  • 0b42a6d6ea4cad492448d11cd282f980bf6cbcc3: fix(helm): pass registry passwords through stdin (Cherry-Pick) (#28834) (@nitishfy)
  • ae10c0c6c3adb996600aa53e3b2a92121953d015: fix(hook): Fixed hook code issues that caused stuck applications on "Deleting" state (Issues #18355 and #17191) (#26724) (@nikos445)
  • 4d2b6fa94090c9e20584375817e391ecf92eb5ce: fix(hydrator): align dry source validation cache keys with hydrator (#27182) (@agaudreault)
  • 8c29202f1c60e75de976760cf96817c1f9f88a75: fix(hydrator): fix race condition in status update with hydrate annotation (#27183) (@agaudreault)
  • f298f4500f7e060a276e84990d3f0f6e42624ddf: fix(hydrator): preserve all source type fields in GetDrySource() (#27189) (@agaudreault)
  • f73e136cc5135d1eb0b1308e2c828dc8aa8c7519: fix(lint): unnecessary nesting (#27815) (@crenshaw-dev)
  • 6a0457a0dcb4ebca26faca72b9ada5b3746c880b: fix(makefile): Run goals with bind mounts on SELinux enabled host (build-ui,build-docs,serve-docs) (#28003) (@olivergondza)
  • 7fa7d82d7c090ae10049cbc0700e085292e0aea8: fix(normalizers): include resource context in failed normalization log (#27769) (@rafaelmfried)
  • d0810e3afc5aa2a359981148d0fb8acf5a622c02: fix(oidc_userinfo): allow userInfo URL to be customized (#27720) (@the-technat)
  • 87d79f9392cc593da26d091864ec6434c6967b04: fix(performance): add cache support for ResolveRevision to reduce Git operations (#27193) (@agaudreault)
  • 5c1b9303eb2e6397146182260ff7947ad1afabd1: fix(progressivesync): check if error == notfound (cherry-pick #28663 for 3.5) (#28670) (@argo-cd-cherry-pick-bot[bot])
  • 4f47dd0afa1952515208156d8a4eb27ca63bc02a: fix(rbac): resolve RBAC regression for project-scoped resources in multi-namespace architecture (#25289) (#26573) (@tcfwbper)
  • 3b60b5ec9b7c9d9fd57accf9cbd3b59ea3f347c2: fix(reposerver): honor depth of referenced source instead of primary source (cherry-pick #28339 for 3.5) (#28340) (@alexandresavicki)
  • f397bf64d632f7fd7eca4798ea07d47936be0ca0: fix(server): Avoid error when attempting a second delete operation (#27495) (@thomastaylor312)
  • 382c507beb853d0b2d0ed9ed63196b2ece8a24fa: fix(server): Cache glob patterns to improve RBAC evaluation performance (#25759) (@Sinhyeok)
  • 4259f467b0d8c6eb12ed9c377c20f6739af9b7bb: fix(server): Ensure OIDC config is refreshed at server restart (#26913) (@OpenGuidou)
  • 91d83d37c431a674656302418f0edee4888318de: fix(server): fix find container logic for terminal (#26858) (@linghaoSu)
  • d6b2be87f0bfc77c66d0c7460be6aa756caa3e1d: fix(server): make server.glob.cache.size optional (#28242) (#28243) (@crenshaw-dev)
  • 1dd9075a7210fb6b19dd14e5541eeb22d79ac91f: fix(settings): only trigger reload for app.kubernetes.io/part-of=argocd secrets (#27213) (@EronWright)
  • 212f51d851dcb15bc84c8bd4e29d6cbdebcf0eca: fix(sharding): fix log format verb and document intentional shard-0 fallback (#27222) (@nitishfy)
  • 8feb146b5213614b1bcc5d8d4e6e6ecf0fc4bb35: fix(ssa): do not run auth reconcile with SSA (#26175) (#27601) (@agaudreault)
  • 134b428d78ca9fdafc63c83e61855decdbe677a8: fix(ssd): regression causing diff to error on new objects (#27679) (#27703) (@agaudreault)
  • 63a009effa8b7aac9ed0315f25ed0b7025e6184f: fix(test): make fail message better for TestAuthReconcileWithMissingNamespace (#26856) (@cjcocokrisp)
  • abf731173cf0e7bc6c51c267721d7e0931b1a5ec: fix(ui): Application Summary crashes on load for non-hydrator apps (#28112) (@agaudreault)
  • b4af746c4fdd9beeffe1e85e9169b53c45aa5a7d: fix(ui): ApplicationSet detail view for non-default namespace (#27928) (#27931) (@AsifAd)
  • 25df43d7a0f042fad792e4cd189daffe9066e1c3: fix(ui): Improve message on self-healing disabling panel (#26977) (#26978) (@bebosudo)
  • 30efe53bf2dfb055ecf17e8b2f6bbe3741bd03e8: fix(ui): OCI revision metadata never renders due to conflicting guard clause (#26948) (#27097) (@karimzakzouk)
  • 30ab5b5b70ed41f81bde4a52f3a386bc9360e8eb: fix(ui): adapt new applicationset icon test to react-testing-library (@jwinters01)
  • 993533a717d78a739cc49ffd84fefb75e9e6e1a0: fix(ui): add icon for view.promoter.argoproj.io API group (#28246) (#28247) (@crenshaw-dev)
  • 1bd0d48c82459111a9741d3a443762228a15bf2f: fix(ui): add truncation and tooltip for long sync status branch names (#27260) (@choejwoo)
  • a5012a0be10a20fe1cbf611c3175472a7e1ef50e: fix(ui): add url origin to return_url (#27733) (@Sumis34)
  • f6ade146276baae891f6af866a21af5904974849: fix(ui): app/appset size of ResourceIcon (#28141) (@agaudreault)
  • 0c80d136cac81d86377fac282c2ba4351104a35f: fix(ui): avoid mutating toolbar input in AddAuthToToolbar (@jwinters01)
  • 8206eb972ebd3d95474c9cb0515d923281f0180d: fix(ui): contain settings textareas within panel width (#27943) (@choejwoo)
  • d1d0e5d10d8f2db6ff9cc23373f2916aada5aa40: fix(ui): don't prefetch errors (#27877) (#27925) (@blakepettersson)
  • 4fbe92afc24238e5a0fd7b2faf620b13a6ea623d: fix(ui): guard against undefined groupName in project role groups edit (@jwinters01)
  • 8e2571fdcab7a009fed5e8f1a261cd9808bd9181: fix(ui): handle 401 error in stream (#26917) (@linghaoSu)
  • 2653f25ee776239d56d40fc2cdfbde205f05a3ac: fix(ui): include Deleting and Terminated apps in Syncing operation filter (#27874) (@choejwoo)
  • 4b4bbc8bb22c05c258b15eceb5f4cabc646e8885: fix(ui): include _-prefixed dirs in embedded assets (#26589) (@choejwoo)
  • 9a05e0e7f391d8f5fccdc800f430c7c36162e515: fix(ui): placate sonar with adding compare function for repo path sort autocomplete (#26906) (@reggie-k)
  • 54531728fa1d854a6a095b422b6f09dd18886b85: fix(ui): prevent pod logs viewer crash on stale container index (#27553) (@youhonglian)
  • b6a715c118ecf7e766d038598a773e5d4ac5948d: fix(ui): prevent wide gaps in grouped resource tree (#25747) (@choejwoo)
  • 566c62259920eae47da31afde71f6faadf8670ef: fix(ui): reduce loaded application data on list operation (Relates [#15509]) (#25451) (@aveuiller)
  • 3c889f4e5bc1835e09f19304d366f4b4e92912b8: fix(ui): regenerate pnpm-lock.yaml against public npm registry (@jwinters01)
  • a39953d21f51d7403d2b4b8fe0ba1425aa4d5751: fix(ui): remove auto-sync toggle from app top bar (#27868) (@shiiyan)
  • b1db1b1b134100842983032b5d4df2c553c8e7d3: fix(ui): restore public registry tarball URLs in pnpm-lock.yaml (@jwinters01)
  • fc821b8a4162caa01b41faefbb5e0ce7ddbf21d3: fix(ui): restore token diff highlighting in resource diff view (@jwinters01)
  • 26621ad0d9318b49b52ae537ec6887bb87b5a292: fix(ui): return full source for non-hydrator apps in Parameters tab (#26946) (@himeshp)
  • 45b926d796822105cc673b3f168b0ba7782b3f4b: fix(ui): show clear-all button for annotation-only filters (#26937) (@choejwoo)
  • bc5d359c86d68a55250bedd624a86dfce239486a: fix(ui): update cluster count logic in ApplicationsSummary (cherry-pick #28768 for 3.5) (#28777) (@argo-cd-cherry-pick-bot[bot])
  • 9fb0c8ce893501d24e4e4d5e4bccb210c15bc6c3: fix(ui): wrap component in AppContextReact.Provider (#28131) (@blakepettersson)
  • 3e015945fdb7e2f2ea33369238ce5bbc81160102: fix(ui):ArgoCD UI Displays Layouts Before Login Page (#25463) (@aali309)
  • 68cbd05e520aaeadb4a9fa7b68abb37e8f3d5043: fix: Add X-Frame-Options and CSP headers to Swagger UI endpoints (#26521) (@rohansood10)
  • 0aa8c41e164bdaad994dffe87832410e116aaea2: fix: ApplicationSet DuckType Generator panics on non-string values in Clus… (#27265) (@xiangjingli)
  • d011b7b5089f1b784fc1911bf9fe99143868aa82: fix: Bitbucket webhook diffstat does not work with upper case repo slug (#26594) (@Mangaal)
  • 4535a1fde7b9fae3d08f231dc955972fcd3b0027: fix: Don't mark CRD degraded while 'Installing' (#26126) (@kbweave)
  • c70acd502446c47228eb8de257b52bdbf2177ded: fix: GetRefSources populates refSources for multi source app with a single source (#27787) (@reggie-k) *

v3.4.6

Jul 31, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.6/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.6/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • aa9970b380b8c2e9e7cb9bc93be08b52fc9164a1: fix(appset): fall back to create when patch returns NotFound (#17312) (cherry-pick #28645 for 3.4) (#28718) (@rickbrouwer)
  • 9a91802c48b074fec01e1b07949c4e55caf146f8: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (cherry-pick #28819 for 3.4) (#28894) (@argo-cd-cherry-pick-bot[bot])
  • 4907a99fd2948bc0db78b0a9347cd3077dbba9f7: fix(helm): pass registry passwords through stdin (#17821) (#28835) (@nitishfy)
  • b6d7c82be121ce650749bf07c8ece119313781dc: fix: mount argocd-cmd-params-cm in repo-server so pprof can be enabled (cherry-pick #28863 for 3.4) (#28864) (@argo-cd-cherry-pick-bot[bot])
  • cf7c4a73ffd6a9c41e245295cec30a1da21e17db: fix: only do annotation backfill if live unset (cherry-pick #28770 for 3.4) (#28776) (@argo-cd-cherry-pick-bot[bot])
  • a3d8e280627905ff58d47e1dc84ea2965bfad7b8: fix: progressive sync fixes (3.4 cherry-picks) (#29000) (@blakepettersson)
  • 2aa646b934fb5b48f9c03d8dee134a8870f08b10: fix: use Entra ID uti claim as token id when jti is absent (#28625) (cherry-pick #28656 for 3.4) (#28676) (@argo-cd-cherry-pick-bot[bot])
  • 275d11ec49199ea83d6532d18a6ed6d2790150c7: fix: use OIDC refresh tokens to renew expired sessions (#27041, #12189) (cherry-pick #27777 for 3.4) (#28688) (@argo-cd-cherry-pick-bot[bot])
Other work
  • e1becb74c728a992804d39c3ceb2e9e6ae58f0ae: chore: bump version to 3.4.6 on release-3.4 branch (#28959) (@github-actions[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.5...v3.4.6

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.3.13

Jul 31, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.13/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.13/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 1853165f399f73d1ec567e6d7d8f4adc62c4d711: fix(health): configconnectorcontext and configconnector (#26308) (#26309) (3.3) (#28611) (@crenshaw-dev)
  • 2536ce315f8bf29b23e1519e85bff65038ac18b0: fix(helm): pass registry passwords through stdin (#17821) (cherry-pic… (#28836) (@nitishfy)
  • 853e2c0caea4efd2ef7d2dcb3254d5b631e58a46: fix(reposerver): honor depth of referenced source instead of primary source (cherry-pick #28339 for 3.3) (#28342) (@alexandresavicki)
  • fac2752f152560331da5e0e96181e5e737fb80ba: fix(ssa): do not run auth reconcile with SSA (cherry pick of #28027 and #27601 to 3.3) (#28266) (@akhilnittala)
  • d73c512462fbfb55f32509cd4184ff5dc9e28aac: fix: Revert "fix: avoid calling UpdateRevisionForPaths unnecessary (#25151)" (cherry-pick #27241 for 3.3) (#28949) (@ranakan19)
  • 91a603b8059d12fb3ee1653304990f70823ca813: fix: deleted resource are incorrectly shown in UI (cherry-pick #28322 for 3.3) (#28336) (@argo-cd-cherry-pick-bot[bot])
  • f6faa38bb234cc32e34da5903a42a2dbf9eb739d: fix: don't clobber non-ignored fields on "replace" (cherry-pick #27136 for 3.3) (#28506) (@argo-cd-cherry-pick-bot[bot])
  • ea08dfae730aad73963b7e41d506f8c9913063d1: fix: fixes a regression of dex config env vars substituion - Cherry pick of #28369 in 3.3 (#28410) (@ppapapetrou76)
  • 28d47f473d22055b290fde431a1650e13235ee8f: fix: mount argocd-cmd-params-cm in repo-server so pprof can be enabled (cherry-pick #28863 for 3.3) (#28865) (@argo-cd-cherry-pick-bot[bot])
Dependency updates
  • 676d6f58ee5b434d190b05b882cd661dfab3de7e: chore(deps): bump form-data to 4.0.6 in /ui for fixing CVE-2026-12143 (#28831) (@alkakumari016)
  • 5aa0befdbc1e359b49209b5d1948a0aa02ad4446: chore(deps): bump golang.org/x/crypto to 0.53.0 (release-3.3) (#28338) (@nmirasch)
Other work
  • 58a3ab2df2390717685809caa0d0d180dc0bf70e: chore: bump version to 3.3.13 on release-3.3 branch (#28960) (@github-actions[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.3.12...v3.3.13

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.5.0-rc3 (pre-release)

Jul 28, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0-rc3/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0-rc3/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Features
  • 41b6fee59d67b8ba22bba995a7c0bbc44eb2512f: feat(impersonation): allow to disable strict enforcement (#27084) (cherry-pick #27573 for 3.5) (#28595) (@argo-cd-cherry-pick-bot[bot])
Bug fixes
  • 06fae9ddd5798ff1be10c007624174673d31eb1b: fix(appset): fall back to create when patch returns NotFound (#17312) (cherry-pick #28645 for 3.5) (#28716) (@argo-cd-cherry-pick-bot[bot])
  • a62624ae60e70e1e16b379dd8fae66dfc67282fd: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (cherry-pick #28819 for 3.5) (#28895) (@argo-cd-cherry-pick-bot[bot])
  • 0b42a6d6ea4cad492448d11cd282f980bf6cbcc3: fix(helm): pass registry passwords through stdin (Cherry-Pick) (#28834) (@nitishfy)
  • 5c1b9303eb2e6397146182260ff7947ad1afabd1: fix(progressivesync): check if error == notfound (cherry-pick #28663 for 3.5) (#28670) (@argo-cd-cherry-pick-bot[bot])
  • bc5d359c86d68a55250bedd624a86dfce239486a: fix(ui): update cluster count logic in ApplicationsSummary (cherry-pick #28768 for 3.5) (#28777) (@argo-cd-cherry-pick-bot[bot])
  • b6bff3b3d4f35fc4ea113b59eafdc4e8046e4ba4: fix: mount argocd-cmd-params-cm in repo-server so pprof can be enabled (cherry-pick #28863 for 3.5) (#28866) (@argo-cd-cherry-pick-bot[bot])
  • 061bd2bd3f7f9bafc6de79563a8e52c2c6c6caa2: fix: only do annotation backfill if live unset (cherry-pick #28770 for 3.5) (#28775) (@argo-cd-cherry-pick-bot[bot])
  • f1b39c88b8997dc87f6909e4e2b845474f05e8b6: fix: use Entra ID uti claim as token id when jti is absent (#28625) (cherry-pick #28656 for 3.5) (#28675) (@argo-cd-cherry-pick-bot[bot])
  • 7cde9f43784e956bb69b304ddeaf0e9f7b1f64dd: fix: use OIDC refresh tokens to renew expired sessions (#27041, #12189) (cherry-pick #27777 for 3.5) (#28689) (@argo-cd-cherry-pick-bot[bot])
Other work
  • 7660efb23b2d56bf01b0189ba5e2c2ab12badf71: chore: bump version to 3.5.0-rc3 on release-3.5 branch (#28938) (@github-actions[bot])
  • faaa0b66df1b4e8016cc630ef9b1d3db30b8c40e: fix(repo-server): honor ARGOCD_REPO_SERVER_OTLP_HEADERS in repo-server (Cherry-pick - 3.5) (#28715) (@nitishfy)
  • 8ffead8d98ad0987686c2c5c77b7be38dc2ddefc: test(e2e): fix github's failure to show complete results of e2e test (#28727) (cherry-pick #28726 for 3.5) (#28728) (@argo-cd-cherry-pick-bot[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.0-rc2...v3.5.0-rc3

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.4.5

Jul 9, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.5/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.5/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • e77e4b645cc1ad28b1af74931d8810c514fa75e7: fix(reposerver): honor depth of referenced source instead of primary source (cherry-pick #28339 for 3.4) (#28341) (@alexandresavicki)
  • 63e67d5e7f502f85b69cd52d6d56e1123b087992: fix(ssa): do not run auth reconcile with SSA (cherry pick of #27624 and #27601 to 3.4) (#28265) (@Mangaal)
  • 240390732e7b593a53a237c4f149426e7268f295: fix: auto-sync skipped when newer commit arrives during sync with manifest-generate-paths (#27875) (cherry-pick #28227 for 3.4) (#28331) (@argo-cd-cherry-pick-bot[bot])
  • 2d18587a4c36d4676dd0514bc4a3c5e0cc8b2ed4: fix: deleted resource are incorrectly shown in UI (cherry-pick #28322 for 3.4) (#28337) (@argo-cd-cherry-pick-bot[bot])
  • a82e158db8a56037d8e8b5085d188abd9fba12f0: fix: don't clobber non-ignored fields on "replace" (cherry-pick #27136 for 3.4) (#28507) (@argo-cd-cherry-pick-bot[bot])
  • d4c8f1c3c724d4d71c1f4ddb6b255ab36d3bef4a: fix: fixes a regression of dex config env vars substituion - Cherry pick of #28369 in 3.4 (#28411) (@ppapapetrou76)
Dependency updates
  • 8c7ece50a4dfd731d5e10bedf3a3e692808b3d23: chore(deps): bump golang.org/x/crypto to 0.53.0 (release-3.4) (#28375) (@nmirasch)
  • a8f245b7a0a9b4b9ca8538038b521da29b5932f6: chore(deps): update Ubuntu base image to 26.04 LTS (3.4) (#28430) (@suii2210)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.4...v3.4.5

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.5.0-rc2 (pre-release)

Jul 1, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0-rc2/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.0-rc2/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 3b60b5ec9b7c9d9fd57accf9cbd3b59ea3f347c2: fix(reposerver): honor depth of referenced source instead of primary source (cherry-pick #28339 for 3.5) (#28340) (@alexandresavicki)
  • 5fa6fd3f2604d2fcdc7a67d097681d98e6149c32: fix: Watch APIServices like we do CRDs (cherry-pick #28289 for 3.5) (#28320) (@argo-cd-cherry-pick-bot[bot])
  • 5d039f81f8c2ab7752b0e7fbd6b9a6db14492b1c: fix: add a lock on clusterinformer (cherry-pick #28216 for 3.5) (#28311) (@argo-cd-cherry-pick-bot[bot])
  • 9a5c6b71a678a72e41d114c97bc053133bd876f0: fix: auto-sync skipped when newer commit arrives during sync with manifest-generate-paths (#27875) (cherry-pick #28227 for 3.5) (#28332) (@argo-cd-cherry-pick-bot[bot])
  • bc04869cd45e63523045222955d74433cd646c8e: fix: deleted resource are incorrectly shown in UI (cherry-pick #28322 for 3.5) (#28335) (@argo-cd-cherry-pick-bot[bot])
  • 54fa590345032f0f9ced81e27c37bac61ddb1df9: fix: don't clobber non-ignored fields on "replace" (cherry-pick #27136 for 3.5) (#28505) (@argo-cd-cherry-pick-bot[bot])
  • bec3925bf022c8fb107b227112347b8d4a145577: fix: fix failure on Sync of resources that do not fit into last-applied-configuration (#28421) (cherry-pick #28440 for 3.5) (#28523) (@argo-cd-cherry-pick-bot[bot])
  • a5e6a2e8bbd203ef6475dce1a2eebf4bf24941c0: fix: fixes a regression of dex config env vars substituion - Cherry pick of #28369 in 3.5 (#28409) (@ppapapetrou76)
  • cb882f37c81f4a64ca97370fc3547afdd7d9c147: fix: normalize Helm valuesObject in source comparison to avoid spurious appdetails 403 (#28288) (cherry-pick #28318 for 3.5) (#28334) (@argo-cd-cherry-pick-bot[bot])
  • 0b95bbc14bc8fe04cd2e698d6c7ffb8d5a1b9ea8: fix: replace k8s.io/cri-streaming (cherry-pick #28315 for 3.5) (#28319) (@argo-cd-cherry-pick-bot[bot])
Other work
  • 972e46b44eb7ab1b5a82eea8e7150cdb79dbde3c: chore: switch reconcile trigger log to info level for managed resource (cherry-pick #28456 for 3.5) (#28519) (@argo-cd-cherry-pick-bot[bot])

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.0-rc1...v3.5.0-rc2

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

v3.4.4

Jun 18, 2026
Quick Start
Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.4/manifests/install.yaml
HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.4.4/manifests/ha/install.yaml
Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog
Bug fixes
  • 146184ea41fa545e0a084c82f05cfe5bd07a9ff9: fix(health): PromotionStrategy stuck Progressing after no-op re-hydration (#28124) (cherry-pick #28125 for 3.4) (#28135) (@argo-cd-cherry-pick-bot[bot])
  • e515f51ab1ca500a165b49ca9ec9c402279b6768: fix(rbac): resolve RBAC regression for project-scoped resources in multi-namespace architecture (#25289) (#26573) (#28062) (@wanddynosios)
  • 7f2fe9576c6b426f00b04abe6dea55cc9cf634c3: fix(ssd): regression causing diff to error on new objects (#27679) (cherry-pick #27703 for 3.4) (#28241) (@argo-cd-cherry-pick-bot[bot])
  • 5199ea6cb74471e22b9c007b0c4598575bb37e44: fix: add a lock on clusterinformer (cherry-pick #28216 for 3.4) (#28312) (@blakepettersson)
  • 7a64081225fe7e9688cd7a3d0ad0ff2bc62fde78: fix: exclude live status from normalization (cherry-pick #28201 for 3.4) (#28204) (@argo-cd-cherry-pick-bot[bot])
  • 0b3436ffe67564506a49007970daa3d9f476856d: fix: fixes parsing of dex passwords with dollar sign (cherry pick of #28027 to 3.4) (#28197) (@ppapapetrou76)
  • 9ccf66b8fc4500d90091075debed86dc218a3981: fix: resolve cross-generator Values templates in RenderGeneratorParams (#27827) (cherry-pick #27830 for 3.4) (#28128) (@argo-cd-cherry-pick-bot[bot])
Other work
  • 14ad471bf6102535664cac3b43cb706904c72b35: Merge pull request #28162 from argoproj/cherry-pick-28158-to-release-3.4 (@dudinea)
  • 0fd000b25fb94fbc2de25dd3c97417e44d28a629: Merge pull request #28164 from argoproj/cherry-pick-28155-to-release-3.4 (@dudinea)
  • ff255193d14b0ab7ecf7bea48c9cfda3cc0de46a: chore(ci): bump codecov action to 7.0.0 to fix the GPG issue (cherry-pick #28159 for 3.4) (#28172) (@dudinea)
  • e9ff0c571b905989d517ac377c4071b6b6180081: ci: bump goreleaser (cherry-pick #28033 for 3.4) (#28072) (@argo-cd-cherry-pick-bot[bot])
  • 1c5e37da077808446895092764bd14312c53d76d: ci: use github release notes in goreleaser (cherry-pick #28048 for 3.4) (#28071) (@argo-cd-cherry-pick-bot[bot])
  • 0c14cfb5117526dd35657e0fddd21c5c612664be: fix(manifest-generate-paths): Normalize repo before using type repo (#28113) (@fm1ck3y)
  • c2003f447e49a183b75e3d94e7982c59c012bd5e: test(e2e): Add test for second Sync after initial for different resources/options (#28156) (#28155) (@dudinea)
  • 9810fa2902e60e48df2acda2353f44b293d4203f: test(e2e): fix cleanup of CRDs for e2e tests (#28157) (#28158) (@dudinea)

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.4.3...v3.4.4

<a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a>

Claim your changelog — free