← Back to all sparks
T

Tyk

INFRA · APIS
Velocity5.0

Open source API gateway and management platform

Tyk's release feed is CVE dependency bumps across three maintained lines.

api-gatewaydependency-securitymulti-version-supportgateway-telemetry
◆Current state
Tyk is cutting release candidates on several maintained lines at once (5.8, 5.13, 5.15) and nearly all of them carry the same dependency bump for a batch of CVEs: kin-openapi, golang.org/x/crypto, thrift and the OTLP trace exporters. The one feature entry is the 5.16.0 alpha, where the gateway sends node metadata when it registers.
◆Where it's heading
The work is supply-chain maintenance spread across a wide support window, with feature work happening on the 5.16 alpha line. Gateway registration metadata hints at better fleet visibility from the control plane, but one ticket is not enough to call a direction.
◆Prediction
Expect the CVE bumps to go final across 5.13 and 5.15 and more 5.16 alphas; what 5.16 adds beyond gateway registration isn't visible yet.

◆Recent moves

  1. 1d ago

    5.13.4-rc1: dependency bumps for CVE fixes

    Brings the TT-18285 dependency bumps to the 5.13 line again. It is part of the same CVE sweep running across every supported version.

    View source ↗
  2. 3d ago

    5.16.0 alpha: gateways report node metadata on registration

    The first 5.16 alpha has the gateway send node metadata when it registers. It's the only feature work in the feed, pointing to better fleet visibility while the stable lines get security patches.

    View source ↗
  3. 8d ago

    5.15.1-rc3: OTLP trace exporter bump

    Bumps the OTLP trace exporters on the 5.15.1 candidate as part of the CVE sweep. No behaviour change described.

    View source ↗
  4. 8d ago

    5.13.3-rc3: OTLP trace exporter bump

    The same OTLP exporter bump applied to the 5.13.3 candidate minutes after 5.15.1-rc3. Dependency maintenance.

    View source ↗
  5. 9d ago

    5.13.3-rc1: dependency bumps for CVE fixes

    The first 5.13.3 candidate with the TT-18285 CVE dependency bumps. It opens the cross-version patch sweep.

    View source ↗
  6. 9d ago

    v5.15.1-rc1: Merging to release-5.15: Fix/tt 18285/bump dependencies (#8736) (#8739)

    View source ↗