live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

OpenShift Dev Spaces 3.29.1 closes security gaps across the workspace stack

The Important update replaces 17 Dev Spaces images across operator, IDE, gateway and registry paths; administrators should verify both the control plane and running workspaces.

By The News Desk· Aug 21, 2026

Red Hat has rated the OpenShift Dev Spaces 3.29.1 advisory Important and lists 17 CVEs in the July 29 update. The breadth matters: this is not a single server-image replacement. The advisory publishes new images for the operator and bundle, Dev Spaces server and dashboard, browser IDE and SSH path, registries, reverse proxy, OAuth proxy, workspace base images and supporting services.

Where exposure sits

The updated amd64 set covers devspaces-rhel9-operator and its bundle; server-rhel9 and dashboard-rhel9; code-rhel9, code-sshd-rhel9 and jetbrains-ide-rhel9; pluginregistry-rhel9 and openvsx-rhel9; traefik-rhel9, oauth2-proxy-rhel9 and multicluster-redirector-rhel9; plus configbump, imagepuller, UDI and UDI base images. Red Hat also supplies rebuilt images for s390x, ppc64le and arm64.

That inventory gives administrators a practical exposure map. Internet- or intranet-facing routes terminate through dashboard, server and proxy components; developer-supplied code executes inside IDE and UDI images; extensions arrive through registry paths; and reconciliation depends on the operator. A cluster can therefore appear updated at the subscription level while old workspace pods or cached images remain in service.

The advisory says Dev Spaces 3.29 is based on Eclipse Che 7.119 and the DevWorkspace engine, supports devfile 2.1 and 2.2, and requires supported OpenShift EUS releases 4.16 or newer. Red Hat also directs devfile v1 users to migrate.

Update and verify

  1. Confirm the Dev Spaces subscription resolves to 3.29.1 and that earlier applicable errata have been installed.
  2. Record current CSV, operator deployment and image digests before the change; compare them with the architecture-specific digests in RHSA-2026:48124 afterward.
  3. Wait for the Dev Spaces custom resource and operator deployment to report healthy reconciliation, then check dashboard, server, proxy and registry pods for restarts or image-pull failures.
  4. Stop and recreate representative workspaces so IDE, SSH, UDI and helper containers no longer use pre-update images. Do not treat an updated operator alone as proof that existing pods were replaced.
  5. Test sign-in, dashboard loading, workspace creation, extension discovery, terminal access and repository cloning through the normal route.
  6. On GPU or multi-architecture fleets, verify the nodes actually pulled the digest published for their architecture.
  7. Check for devfile v1 workspaces and schedule their migration separately; the security update does not remove that compatibility work.

The decisive post-upgrade evidence is a clean set of running image IDs plus successful workspace lifecycle tests—not merely an installed CSV named 3.29.1.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.