Releases: envoyproxy/envoy
Release list
v1.39.0
Summary of changes
Breaking changes
- build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode,
--enable_workspaceand--noenable_bzlmodare required and have been added to.bazelrc; external-repository runfiles now appear directly under the runfiles root. - build: the Intel DLB connection balancer (
envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source archive. - TLS:
enforce_rsa_key_usageis deprecated and ignored; Envoy now always enforces the certificatekeyUsageextension. - TLS inspector: client TLS versions are validated and must be between TLS 1.0 and TLS 1.3 (revertible via
envoy.reloadable_features.tls_inspector_enforce_client_tls_version). - OpenTelemetry tracing: the tracer now honors Envoy's request-entry sampling decision, including
overall_sampling, even when propagated trace context or the configured sampler requests sampling. This may reduce exported spans.
Security
- HTTP/2 now counts uncompressed cookies toward header-size and header-count limits (CVE-2026-47774), strengthens PRIORITY/WINDOW_UPDATE flood protection, and adds configurable nghttp2 RST_STREAM rate limits.
- HTTP/3 fixes cover QPACK blocked-decoding denial of service (GHSA-p7c7-7c47-pwch) and inconsistent headers-only
content-lengthhandling (CVE-2026-48743). - Security fixes were added for ext_authz (CVE-2026-47205), ext_proc (CVE-2026-47207), gRPC stats (CVE-2026-47204), internal redirects (CVE-2026-47221), and OAuth2 lifecycle handling (CVE-2026-48090).
- OAuth2 adds AES-256-GCM cookie encryption to address CVE-2026-47775. Migration is opt-in: enable
oauth2_use_gcm_encryption, monitoroauth_legacy_cbc_decrypt, then disableoauth2_legacy_cbc_decrypt_compat. - Additional fixes cover DNS query validation (CVE-2026-48497), JSON nesting limits (CVE-2026-48042), PROXY protocol TLV smuggling (CVE-2026-47692), formatter crashes (CVE-2026-47220), TCP StatsD overflow (CVE-2026-48706), TLS SAN NUL handling (CVE-2026-47778), and Zstd decompression memory exhaustion (CVE-2026-48044).
- New upstream RBAC and dynamic-forward-proxy resolved-address filtering provide CIDR-based protection against SSRF after DNS resolution and host selection.
Dynamic modules
- New extension points: access-log/header formatters, downstream and upstream transport sockets, active health checkers, and stats sinks.
- Cluster load balancers can read host stats, read and write dynamic metadata and filter state, and publish main-thread state to worker-local slots.
- Modules can emit metrics from configuration and background contexts; loading and initialization failures now expose server-wide counters tagged by extension instance.
- Added validation-mode detection, network/listener attribute access, batched header and metadata APIs, effective log-level access, and zero-copy borrowed buffers in the Rust SDK.
- Fixed listener HTTP-callout crashes, watermark initialization, streaming-response re-entry, independent decode/encode continuation, CatchUnwind re-entry,
Structconfiguration handling, and HTTP/TCP bridge buffer overflow with more than 64 slices.
MCP (Model Context Protocol) and AI protocols
- Added a Wuffs-backed streaming JSON parser for MCP, A2A, OpenAI, Anthropic, and related protocols, with bounded field capture, incremental parsing, no DOM allocation, and duplicate-key detection.
- MCP filtering now exposes processing status, supports configurable duplicate-key rejection, and improves oversized-body behavior for pass-through and rejection modes.
- MCP router adds elicitation and server-to-client request routing, plus lazy per-backend initialization.
- MCP JSON REST Bridge adds per-route tool configuration and locally generated
tools/listresponses.
HTTP, routing and protocol
- New HTTP filters provide weighted bandwidth sharing and selectable sub-filter chains with per-route configuration.
HeaderMatchernow evaluates separately supplied header values individually instead of matching only their comma-joined representation (revertible viaenvoy.reloadable_features.match_headers_individually).- HTTP inspector uses Balsa by default and now fast-fails invalid non-HTTP method bytes instead of buffering up to 64 KiB.
- Added drain-timeout and maximum-connection-duration jitter to reduce synchronized reconnect spikes.
- Routing gains cluster refresh on retries, weighted-cluster reselection, formatter/CEL-based redirect paths, and mixed literal/variable URI-template segments.
- Fixed connection-pool re-entrancy, connectivity-grid teardown and duplicate-attempt bugs, stale on-demand cluster information, and handling of HTTP/2 or HTTP/3
RST_STREAM(NO_ERROR)after complete responses.
TLS, authentication and authorization
- Added CNSA 1.0/2.0 compliance policies, TLS group formatters for identifying post-quantum key exchange, and suppression of oversized client CA lists.
- QUIC supports opt-in TLS key logging and session-ticket resumption.
- TLS certificate compression via the brotli runtime guard is disabled by default; TLS sockets also gain improved connection-reset reporting.
- OAuth2 adds
PRIVATE_KEY_JWT, ID-token forwarding, configurable post-logout redirects, access-token-based cookie lifetime, and safe original-request URI formatting with redirect-domain allowlists. - BasicAuth supports missing-credential pass-through and authenticated-username metadata; JWT extraction can mark forwarded claims whose signatures were not verified.
DNS, load balancing and upstream
- The unified DNS cluster implementation is enabled by default; equivalent c-ares resolvers can be shared across clusters to support shared qcache.
- DNS clusters gain a minimum TTL refresh floor, while dynamic forward proxy sub-clusters can use
DnsClusterconfiguration and resolved-address CIDR filtering. - Client-side weighted round robin adds out-of-band ORCA reporting with configurable port, authority, and transport socket matching.
- Least-request load balancing can optionally account for pending requests, with a new per-endpoint pending-request gauge.
- Fixed EDS hostname updates, load reports containing only custom metrics or completed requests, and dynamic-forward-proxy lookup teardown.
Networking and system performance
- Linux deployments gain worker CPU affinity and an
SO_REUSEPORTBPF connection balancer for CPU-local connection steering. - Added a Linux sockmap socket interface for accelerating same-host TCP traffic through eBPF.
- io_uring adds multishot receives, adaptive read buffers, and configurable write backpressure.
- Reverse tunnels gain opt-in GOAWAY-aware draining and replacement; MySQL proxy adds downstream TLS termination with
caching_sha2_passwordmediation. - Added UDP proxy external authorization, network ext_proc metadata reception, and early external-processor stream closure.
Observability
- New access-log data includes upstream TLS SNI and HTTP/TCP downstream/upstream connection duration points; gRPC access logging adds delivery success/failure counters.
- Added dynamic-module and Wasm programmable stats sinks, OpenTelemetry metric request chunking, endpoint observability names, and default-tag overrides.
- Prometheus scraping and large-scale stat-reference release are substantially faster;
/peak_heap_dumpexposes tcmalloc's peak heap profile. - Added process-wide Lua and Wasm VM gauges, single-entry stack traces, and an Envoy-version log-format token.
- Tap now honors configured runtime sampling and reports sampled-out requests/connections.
Rate limiting and configuration
- Rate limiting adds static and dynamic per-descriptor limit overrides, zero-token always-reject behavior, and configurable response-metadata namespaces.
- GCP authentication supports bound access tokens, bound JWTs, and unbound access tokens from the metadata server.
- Added file-backed IP tagging, in-place watched-file modification events, runtime-adjustable fixed-heap limits, health-check HTTP status events, and xDS unsubscribe callbacks.
- Redis proxy adds Redis 7.4 hash-field expiry commands and permits custom commands inside transactions.
Other notable changes and fixes
- Fixed Hickory DNS resolver leaks and use-after-free, file-server cancellation use-after-free, Golang filter re-entry, outlier-detection teardown, missing network namespaces, and asynchronous TLS close handling.
- Fixed RTDS guard removal, VHDS subscriptions, Wasm VM cache invalidation when environment variables change, and upstream Wasm metric scoping.
- Improved UDP proxy attempted-host and address logging, Zipkin timestamp trace IDs, gRPC access-log failure accounting, and health-check event detail.
- Added TCP proxy delayed route selection, drain-close handling, and connection-duration access logging.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.0
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.0/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.0/version_history/v1.39/v1.39.0
Full changelog:
v1.38.0...v1.39.0
Signed-off-by: Kateryna Nezdolii [email protected]
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Jonh Wendell [email protected]
v1.38.3
Summary of changes:
-
Security fixes:
- CVE-2026-47205: Authz per route crash
- CVE-2026-47207: ext_proc response in one gRPC message
- CVE-2026-47221: router internal redirects crash
- CVE-2026-47220: REQUESTED_SERVER_NAME crash
- CVE-2026-47775: OAuth2 code verifier padding oracle
- CVE-2026-48044: zstd RLE zip bomb
- CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
- CVE-2026-48042: Stack overflow in destructor of highly nested JSON
- CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
- CVE-2026-48497: Abnormal process termination in DNS UDP filter
- CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
- CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
- GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
-
Upstream security fixes:
- CVE-2026-47261: wasm: bumped
com_github_wasmtimeto resolve CVE-2026-47261.
- CVE-2026-47261: wasm: bumped
-
Behavior changes:
- build: disabled the contrib extension
envoy.network.connection_balance.dlb(Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
- build: disabled the contrib extension
-
Minor behavior changes:
- tls: runtime guard
envoy.reloadable_features.tls_certificate_compression_brotliis now disabled by default. When disabled, QUIC retains zlib-only certificate compression and TCP TLS performs no certificate compression. It can be re-enabled by setting the runtime guard totrue.
- tls: runtime guard
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.3
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.3/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.3/version_history/v1.38/v1.38.3
Full changelog:
v1.38.2...v1.38.3
Signed-off-by: Greg Greenway [email protected]
Signed-off-by: Jonh Wendell [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Boteng Yao [email protected]
v1.37.5
Summary of changes:
-
Security fixes:
- CVE-2026-47205:Authz per route crash
- CVE-2026-47207: ext_proc response in one gRPC message
- CVE-2026-47221: router internal redirects crash
- CVE-2026-47220: REQUESTED_SERVER_NAME crash
- CVE-2026-47775: OAuth2 code verifier padding oracle
- CVE-2026-48044: zstd RLE zip bomb
- CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
- CVE-2026-48042: Stack overflow in destructor of highly nested JSON
- CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
- CVE-2026-48497: Abnormal process termination in DNS UDP filter
- CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
- CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
- GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
-
Upstream security fixes:
- CVE-2026-47261: wasm: bumped
com_github_wasmtimeto resolve CVE-2026-47261.
- CVE-2026-47261: wasm: bumped
-
Behavior changes:
- build: disabled the contrib extension
envoy.network.connection_balance.dlb(Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
- build: disabled the contrib extension
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.5/version_history/v1.37/v1.37.5
Full changelog:
v1.37.4...v1.37.5
Signed-off-by: Greg Greenway [email protected]
Signed-off-by: Jonh Wendell [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Boteng Yao [email protected]
v1.36.9
Summary of changes:
-
Upstream security fixes:
- CVE-2026-47205:Authz per route crash
- CVE-2026-47207: ext_proc response in one gRPC message
- CVE-2026-47221: router internal redirects crash
- CVE-2026-47775: OAuth2 code verifier padding oracle
- CVE-2026-48044: zstd RLE zip bomb
- CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
- CVE-2026-48042: Stack overflow in destructor of highly nested JSON
- CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
- CVE-2026-48497: Abnormal process termination in DNS UDP filter
- CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
- CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
- GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
-
Upstream security fixes:
- CVE-2026-47261: wasm: bumped
com_github_wasmtimeto resolve CVE-2026-47261.
- CVE-2026-47261: wasm: bumped
-
Behavior changes:
- build: disabled the contrib extension
envoy.network.connection_balance.dlb(Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
- build: disabled the contrib extension
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.9
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.9/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.9/version_history/v1.36/v1.36.9
Full changelog:
v1.36.8...v1.36.9
Signed-off-by: Greg Greenway [email protected]
Signed-off-by: Jonh Wendell [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Boteng Yao [email protected]
v1.35.13
Summary of changes:
-
Security fixes:
- CVE-2026-47207: ext_proc response in one gRPC message
- CVE-2026-47221: router internal redirects crash
- CVE-2026-47775: OAuth2 code verifier padding oracle
- CVE-2026-48044: zstd RLE zip bomb
- CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled
spillover into the upstream application stream - CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
- CVE-2026-48042: Stack overflow in destructor of highly nested JSON
- CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
- CVE-2026-48497: DNS filter abnormal process termination on long query name
- CVE-2026-48743: HTTP/3 headers-only request/response content-length not validated
- CVE-2026-48706: TcpStatsdSync buffer overflow with large stats name
- GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
-
Upstream security fixes:
- CVE-2026-47261: wasm: bumped
com_github_wasmtimeto resolve CVE-2026-47261.
- CVE-2026-47261: wasm: bumped
-
Behavior changes:
- build: disabled the contrib extension
envoy.network.connection_balance.dlb(Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
- build: disabled the contrib extension
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13
Docs:
https://www.envoyproxy.io/docs/envoy/v1.35.13/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13
Full changelog:
v1.35.12...v1.35.13
Signed-off-by: Greg Greenway [email protected]
Signed-off-by: Jonh Wendell [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Boteng Yao [email protected]
v1.38.2
Summary of changes:
-
Bug fixes:
- runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
-
New features:
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
cookieheader length, and individualcookieheader count. Enable withenvoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release. - http2: added
envoy.reloadable_features.http2_max_cookies_size_in_kbto limit the size of the reassembledcookieheader. By default, no cookie-size limit is enforced.
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.2/version_history/v1.38/v1.38.2
Full changelog:
v1.38.1...v1.38.2
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
v1.37.4
Summary of changes:
-
Bug fixes:
- runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
-
New features:
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
cookieheader length, and individualcookieheader count. Enable withenvoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release. - http2: added
envoy.reloadable_features.http2_max_cookies_size_in_kbto limit the size of the reassembledcookieheader. By default, no cookie-size limit is enforced.
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.4
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.4/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.4/version_history/v1.37/v1.37.4
Full changelog:
v1.37.3...v1.37.4
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
v1.36.8
Summary of changes:
-
Bug fixes:
- runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
-
New features:
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
cookieheader length, and individualcookieheader count. Enable withenvoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release. - http2: added
envoy.reloadable_features.http2_max_cookies_size_in_kbto limit the size of the reassembledcookieheader. By default, no cookie-size limit is enforced.
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.8
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.8/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.8/version_history/v1.36/v1.36.8
Full changelog:
v1.36.7...v1.36.8
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
v1.35.12
Summary of changes:
-
Bug fixes:
- runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
-
New features:
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
cookieheader length, and individualcookieheader count. Enable withenvoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release. - http2: added
envoy.reloadable_features.http2_max_cookies_size_in_kbto limit the size of the reassembledcookieheader. By default, no cookie-size limit is enforced.
- http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.12
Docs:
https://www.envoyproxy.io/docs/envoy/v1.35.12/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.35.12/version_history/v1.35/v1.35.12
Full changelog:
v1.35.11...v1.35.12
Signed-off-by: Ryan Northey [email protected]
Signed-off-by: Kateryna Nezdolii [email protected]
v1.38.1
Summary of changes:
-
Security fixes:
- CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards
mutable_max_request_headers_kbandmax_headers_countlimits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted withenvoy.reloadable_features.http2_include_cookies_in_limits. - oauth2: fixed a timing side-channel in HMAC verification that could leak HMAC secret validity.
- oauth2: fixed a crash where AES-CBC decryption of token cookies could spuriously succeed (~1/256) on a secret mismatch, tripping a
HeaderStringvalidation assert. - CVE-2026-27135: http2: applied nghttp2 CVE-2026-27135 patch.
- CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards
-
Bug fixes:
- dynamic_modules: fixed a crash in the HTTP filter when a stream was already above the downstream write-buffer high watermark at filter-chain construction time.
-
Minor behavior changes:
- router: the upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients (still available in access logs via
%UPSTREAM_TRANSPORT_FAILURE_REASON%). Revert withenvoy.reloadable_features.hide_transport_failure_reason_in_response_body. - upstream: load balancer rebuild coalescing during EDS batch host updates is now opt-in. Re-enable with
envoy.reloadable_features.coalesce_lb_rebuilds_on_batch_update.
- router: the upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients (still available in access logs via
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.1
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.1/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.1/version_history/v1.38/v1.38.1
Full changelog:
v1.38.0...v1.38.1
Signed-off-by: Jonh Wendell [email protected]
Signed-off-by: Greg Greenway [email protected]
Signed-off-by: Ryan Northey [email protected]