---
name: openshift-cl-add-ons-vpc-file-csi-driver
title: VPC File CSI Driver add-on version change log
description: Review the version history for VPC File CSI Driver.
last-updated: 2026-10-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/openshift?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# VPC File CSI Driver add-on version change log
{: #cl-add-ons-vpc-file-csi-driver}


Patch updates
:   Patch updates are delivered automatically by IBM and don't contain any feature updates or changes in the supported add-on and cluster versions.

Release updates
:   Release updates contain new features or changes in the supported add-on or cluster versions. You must manually apply release updates to your cluster autoscaler add-on.

To view a list of add-ons and the supported cluster versions, run the following command or see the [Supported cluster add-ons table](https://cloud.ibm.com/docs/openshift?topic=openshift-supported-cluster-addon-versions&format=markdown).

```sh
ibmcloud oc cluster addon versions
```
{: pre}







## Supported versions
{: #cl-add-ons-vpc-file-csi-driver-supported-versions}

| Add-on version | Supported OpenShift versions |
|---|---|
| `2.0` | `>=4.14.0 <4.23.0` |
{: caption="Supported VPC File CSI Driver add-on versions" caption-side="bottom"}




Review the version history for VPC File CSI Driver.
{: shortdesc}


## Version 2.0
{: #cl-add-ons-vpc-file-csi-driver-2.0}


### 29 September 2026, Version 2.0 - v2.0.54_372210496
{: #cl-add-ons-vpc-file-csi-driver-v2054_372210496}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-14456](https://nvd.nist.gov/vuln/detail/cve-2026-14456){: external}, [CVE-2026-14457](https://nvd.nist.gov/vuln/detail/cve-2026-14457){: external}, [CVE-2026-18798](https://nvd.nist.gov/vuln/detail/cve-2026-18798){: external}, [CVE-2026-54874](https://nvd.nist.gov/vuln/detail/cve-2026-54874){: external}, [CVE-2026-63072](https://nvd.nist.gov/vuln/detail/cve-2026-63072){: external}, [CVE-2026-63074](https://nvd.nist.gov/vuln/detail/cve-2026-63074){: external}, [CVE-2026-63075](https://nvd.nist.gov/vuln/detail/cve-2026-63075){: external}, [CVE-2026-63076](https://nvd.nist.gov/vuln/detail/cve-2026-63076){: external}, [CVE-2026-63073](https://nvd.nist.gov/vuln/detail/cve-2026-63073){: external}, [CVE-2026-56391](https://nvd.nist.gov/vuln/detail/cve-2026-56391){: external}, and [CVE-2026-56392](https://nvd.nist.gov/vuln/detail/cve-2026-56392){: external}.
- Fixed crash when handling invalid volumeCapability requests 
- Added default mount options (nfsvers=4.1, sec=sys) for NFS volumes when StorageClass does not specify mountOptions. 
- Added `allowCapacityRoundoffForIops` StorageClass parameter for dp2 volumes — automatically rounds up requested PVC capacity to the minimum GiB needed to satisfy the specified IOPS, using the dp2 profile band table fetched from at driver startup.
- `armada-storage-secret v1.3.66`
- `stunnel:0.1.0.build-37`


### 15 September 2026, Version 2.0 - v2.0.52_369240368
{: #cl-add-ons-vpc-file-csi-driver-v2052_369240368}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/cve-2026-84304){: external}, and [CVE-2026-54371](https://nvd.nist.gov/vuln/detail/cve-2026-54371){: external}.
- `armada-storage-secret v1.3.65`
- `stunnel:0.1.0.build-35`


### 02 September 2026, Version 2.0 - v2.0.51_365773339
{: #cl-add-ons-vpc-file-csi-driver-v2051_365773339}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-33818](https://nvd.nist.gov/vuln/detail/cve-2026-33818){: external}, [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/cve-2026-39821){: external}, [CVE-2026-56853](https://nvd.nist.gov/vuln/detail/cve-2026-56853){: external}, [CVE-2026-56858](https://nvd.nist.gov/vuln/detail/cve-2026-56858){: external}, [CVE-2026-56859](https://nvd.nist.gov/vuln/detail/cve-2026-56859){: external}, [CVE-2026-56860](https://nvd.nist.gov/vuln/detail/cve-2026-56860){: external}, and [CVE-2026-56862](https://nvd.nist.gov/vuln/detail/cve-2026-56862){: external}.
- `armada-storage-secret v1.3.64`
- `stunnel:0.1.0.build-34`


### 26 August 2026, Version 2.0 - v2.0.50_364067134
{: #cl-add-ons-vpc-file-csi-driver-v2050_364067134}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-11940](https://nvd.nist.gov/vuln/detail/cve-2026-11940){: external}.
- `armada-storage-secret v1.3.63`


### 18 August 2026, Version 2.0 - v2.0.49_362519752
{: #cl-add-ons-vpc-file-csi-driver-v2049_362519752}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-41989](https://nvd.nist.gov/vuln/detail/cve-2026-41989){: external}.
- `armada-storage-secret v1.3.62`


### 12 August 2026, Version 2.0 - v2.0.47_360961675
{: #cl-add-ons-vpc-file-csi-driver-v2047_360961675}

[Default version]{: tag-green}

- Resolves the following CVEs: [GO-2026-6061](https://pkg.go.dev/vuln/go-2026-6061){: external}.
- Runs tunnel container as non-root 
- `armada-storage-secret v1.3.61`
- `stunnel:0.1.0.build-32`


### 05 August 2026, Version 2.0 - v2.0.45_359566968
{: #cl-add-ons-vpc-file-csi-driver-v2045_359566968}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-5928](https://nvd.nist.gov/vuln/detail/cve-2026-5928){: external}, [CVE-2026-6238](https://nvd.nist.gov/vuln/detail/cve-2026-6238){: external}, [CVE-2026-5435](https://nvd.nist.gov/vuln/detail/cve-2026-5435){: external}, [GHSA-hrxh-6v49-42gf](https://github.com/advisories/ghsa-hrxh-6v49-42gf){: external}, [CVE-2026-54370](https://nvd.nist.gov/vuln/detail/cve-2026-54370){: external}, and [CVE-2026-54369](https://nvd.nist.gov/vuln/detail/cve-2026-54369){: external}.
- `armada-storage-secret v1.3.60`


### 29 July 2026, Version 2.0 - v2.0.44_358039267
{: #cl-add-ons-vpc-file-csi-driver-v2044_358039267}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-15308](https://nvd.nist.gov/vuln/detail/cve-2026-15308){: external}, [CVE-2025-5278](https://nvd.nist.gov/vuln/detail/cve-2025-5278){: external}, [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/cve-2026-5450){: external}, [CVE-2026-42505](https://nvd.nist.gov/vuln/detail/cve-2026-42505){: external}, [CVE-2026-2303](https://nvd.nist.gov/vuln/detail/cve-2026-2303){: external}, [CVE-2025-58185](https://nvd.nist.gov/vuln/detail/cve-2025-58185){: external}, [CVE-2025-61727](https://nvd.nist.gov/vuln/detail/cve-2025-61727){: external}, [CVE-2025-61729](https://nvd.nist.gov/vuln/detail/cve-2025-61729){: external}, [CVE-2025-47912](https://nvd.nist.gov/vuln/detail/cve-2025-47912){: external}, [CVE-2025-58187](https://nvd.nist.gov/vuln/detail/cve-2025-58187){: external}, [CVE-2025-58188](https://nvd.nist.gov/vuln/detail/cve-2025-58188){: external}, [CVE-2025-58189](https://nvd.nist.gov/vuln/detail/cve-2025-58189){: external}, [CVE-2025-61723](https://nvd.nist.gov/vuln/detail/cve-2025-61723){: external}, [CVE-2025-61724](https://nvd.nist.gov/vuln/detail/cve-2025-61724){: external}, [CVE-2025-61726](https://nvd.nist.gov/vuln/detail/cve-2025-61726){: external}, [CVE-2025-61730](https://nvd.nist.gov/vuln/detail/cve-2025-61730){: external}, [CVE-2025-68121](https://nvd.nist.gov/vuln/detail/cve-2025-68121){: external}, [CVE-2025-47906](https://nvd.nist.gov/vuln/detail/cve-2025-47906){: external}, and [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/cve-2025-22870){: external}.
- Updates Go to version `1.25.12`.
- Fixed incorrect UID/GID assignment for PVCs restored from a snapshot; ownership is now inherited from the source snapshot. 
- Fixed silent PVC mount failures (e.g., NFS exit status 32) that caused Kubelet to mount the local disk instead of failing the mount. 
- [Beta] Encryption in Transit (EIT) support for RFS profile-based storage classes for IKS/ROKS clusters. For experimental use only.
- EIT (Encryption in Transit) support for DP2 profile-based storage classes for ROKS clusters with RHCOS-based worker nodes.
- `armada-storage-secret v1.3.59`
- `csi-provisioner v6.2.0`
- `csi-resizer v2.1.0`
- `csi-livenessProbe v2.18.0`
- `csi-node-driver-registrar v2.16.0`
- `csi-snapshotter v8.5.0`
- `stunnel 0.1.0.build-25`


### 25 June 2026, Version 2.0 - v2.0.37_349678441
{: #cl-add-ons-vpc-file-csi-driver-v2037_349678441}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-34180](https://nvd.nist.gov/vuln/detail/cve-2026-34180){: external}, [CVE-2026-42766](https://nvd.nist.gov/vuln/detail/cve-2026-42766){: external}, [CVE-2026-34183](https://nvd.nist.gov/vuln/detail/cve-2026-34183){: external}, [CVE-2026-42767](https://nvd.nist.gov/vuln/detail/cve-2026-42767){: external}, [CVE-2026-7383](https://nvd.nist.gov/vuln/detail/cve-2026-7383){: external}, [CVE-2026-45446](https://nvd.nist.gov/vuln/detail/cve-2026-45446){: external}, [CVE-2026-42764](https://nvd.nist.gov/vuln/detail/cve-2026-42764){: external}, [CVE-2026-45445](https://nvd.nist.gov/vuln/detail/cve-2026-45445){: external}, [CVE-2026-34181](https://nvd.nist.gov/vuln/detail/cve-2026-34181){: external}, [CVE-2026-42769](https://nvd.nist.gov/vuln/detail/cve-2026-42769){: external}, [CVE-2026-42768](https://nvd.nist.gov/vuln/detail/cve-2026-42768){: external}, [CVE-2026-45447](https://nvd.nist.gov/vuln/detail/cve-2026-45447){: external}, [CVE-2026-34182](https://nvd.nist.gov/vuln/detail/cve-2026-34182){: external}, [CVE-2026-9076](https://nvd.nist.gov/vuln/detail/cve-2026-9076){: external}, and [CVE-2026-42770](https://nvd.nist.gov/vuln/detail/cve-2026-42770){: external}.
- `armada-storage-secret v1.3.56`


### 22 June 2026, Version 2.0 - v2.0.36_347951752
{: #cl-add-ons-vpc-file-csi-driver-v2036_347951752}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-28390](https://nvd.nist.gov/vuln/detail/cve-2026-28390){: external}.
- `armada-storage-secret v1.3.55`


### 09 June 2026, Version 2.0 - v2.0.34_345194711
{: #cl-add-ons-vpc-file-csi-driver-v2034_345194711}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-4438](https://nvd.nist.gov/vuln/detail/cve-2026-4438){: external}, [CVE-2026-4046](https://nvd.nist.gov/vuln/detail/cve-2026-4046){: external}, and [CVE-2026-4437](https://nvd.nist.gov/vuln/detail/cve-2026-4437){: external}.
- `armada-storage-secret v1.3.51`


### 03 June 2026, Version 2.0 - v2.0.33_343448437
{: #cl-add-ons-vpc-file-csi-driver-v2033_343448437}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-33814](https://nvd.nist.gov/vuln/detail/cve-2026-33814){: external}, [CVE-2026-31790](https://nvd.nist.gov/vuln/detail/cve-2026-31790){: external}, [CVE-2026-29111](https://nvd.nist.gov/vuln/detail/cve-2026-29111){: external}, [CVE-2026-40355](https://nvd.nist.gov/vuln/detail/cve-2026-40355){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/cve-2026-40356){: external}, and [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}.
- `armada-storage-secret v1.3.50`


### 29 May 2026, Version 2.0 - v2.0.32_341664893
{: #cl-add-ons-vpc-file-csi-driver-v2032_341664893}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-33811](https://nvd.nist.gov/vuln/detail/cve-2026-33811){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/cve-2026-39979){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/cve-2025-14512){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/cve-2025-14087){: external}, and [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/cve-2026-40164){: external}.
- `armada-storage-secret v1.3.49`


### 13 May 2026, Version 2.0 - v2.0.30_338302575
{: #cl-add-ons-vpc-file-csi-driver-v2030_338302575}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-4786](https://nvd.nist.gov/vuln/detail/cve-2026-4786){: external}, [CVE-2026-6100](https://nvd.nist.gov/vuln/detail/cve-2026-6100){: external}, and [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}.
- `armada-storage-secret v1.2.82`


### 27 April 2026, Version 2.0 - v2.0.28_333900419
{: #cl-add-ons-vpc-file-csi-driver-v2028_333900419}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/cve-2026-32281){: external}, [CVE-2026-32289](https://nvd.nist.gov/vuln/detail/cve-2026-32289){: external}, and [CVE-2026-4519](https://nvd.nist.gov/vuln/detail/cve-2026-4519){: external}.
- Updates Go to version `1.25.9`.
- `armada-storage-secret v1.2.80`


### 07 April 2026, Version 2.0 - v2.0.27_329001706
{: #cl-add-ons-vpc-file-csi-driver-v2027_329001706}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-33186](https://nvd.nist.gov/vuln/detail/cve-2026-33186){: external}.
- Updates Go to version `1.25.8`.
- `armada-storage-secret v1.2.79`


### 24 March 2026, Version 2.0 - v2.0.26_325670948
{: #cl-add-ons-vpc-file-csi-driver-v2026_325670948}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-14831](https://nvd.nist.gov/vuln/detail/cve-2025-14831){: external}, [CVE-2025-15366](https://nvd.nist.gov/vuln/detail/cve-2025-15366){: external}, [CVE-2025-15367](https://nvd.nist.gov/vuln/detail/cve-2025-15367){: external}, [CVE-2026-1299](https://nvd.nist.gov/vuln/detail/cve-2026-1299){: external}, [CVE-2024-6923](https://nvd.nist.gov/vuln/detail/cve-2024-6923){: external}, [CVE-2026-0865](https://nvd.nist.gov/vuln/detail/cve-2026-0865){: external}, [CVE-2026-25679](https://nvd.nist.gov/vuln/detail/cve-2026-25679){: external}, [CVE-2025-12801](https://nvd.nist.gov/vuln/detail/cve-2025-12801){: external}, [CVE-2026-27139](https://nvd.nist.gov/vuln/detail/cve-2026-27139){: external}, and [CVE-2026-27142](https://nvd.nist.gov/vuln/detail/cve-2026-27142){: external}.
- `armada-storage-secret v1.2.78`


### 02 March 2026, Version 2.0 - v2.0.25_321043855
{: #cl-add-ons-vpc-file-csi-driver-v2025_321043855}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2026-0861](https://nvd.nist.gov/vuln/detail/cve-2026-0861){: external}, [CVE-2025-15281](https://nvd.nist.gov/vuln/detail/cve-2025-15281){: external}, and [CVE-2026-0915](https://nvd.nist.gov/vuln/detail/cve-2026-0915){: external}.
- Fixed an issue where EIT enablement was not triggered for new nodes in EIT‑enabled worker pools after a storage operator restart. 
- `armada-storage-secret v1.2.77`


### 26 February 2026, Version 2.0 - v2.0.24_319692587
{: #cl-add-ons-vpc-file-csi-driver-v2024_319692587}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-68121](https://nvd.nist.gov/vuln/detail/cve-2025-68121){: external}, and [CVE-2025-14104](https://nvd.nist.gov/vuln/detail/cve-2025-14104){: external}.
- `armada-storage-secret v1.2.76`


### 10 February 2026, Version 2.0 - v2.0.23_316463584
{: #cl-add-ons-vpc-file-csi-driver-v2023_316463584}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/cve-2025-15467){: external}, [CVE-2025-11187](https://nvd.nist.gov/vuln/detail/cve-2025-11187){: external}, [CVE-2025-15468](https://nvd.nist.gov/vuln/detail/cve-2025-15468){: external}, [CVE-2025-15469](https://nvd.nist.gov/vuln/detail/cve-2025-15469){: external}, [CVE-2025-66199](https://nvd.nist.gov/vuln/detail/cve-2025-66199){: external}, [CVE-2025-68160](https://nvd.nist.gov/vuln/detail/cve-2025-68160){: external}, [CVE-2025-69418](https://nvd.nist.gov/vuln/detail/cve-2025-69418){: external}, [CVE-2025-69419](https://nvd.nist.gov/vuln/detail/cve-2025-69419){: external}, [CVE-2025-69420](https://nvd.nist.gov/vuln/detail/cve-2025-69420){: external}, [CVE-2025-69421](https://nvd.nist.gov/vuln/detail/cve-2025-69421){: external}, [CVE-2026-22795](https://nvd.nist.gov/vuln/detail/cve-2026-22795){: external}, [CVE-2026-22796](https://nvd.nist.gov/vuln/detail/cve-2026-22796){: external}, and [CVE-2025-9086](https://nvd.nist.gov/vuln/detail/cve-2025-9086){: external}.
- `armada-storage-secret v1.2.75`


### 21 January 2026, Version 2.0 - v2.0.22_310489003
{: #cl-add-ons-vpc-file-csi-driver-v2022_310489003}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-13281](https://nvd.nist.gov/vuln/detail/cve-2025-13281){: external}, [CVE-2025-8291](https://nvd.nist.gov/vuln/detail/cve-2025-8291){: external}, [CVE-2025-61729](https://nvd.nist.gov/vuln/detail/cve-2025-61729){: external}, [CVE-2025-61727](https://nvd.nist.gov/vuln/detail/cve-2025-61727){: external}, [CVE-2025-6069](https://nvd.nist.gov/vuln/detail/cve-2025-6069){: external}, [CVE-2024-5642](https://nvd.nist.gov/vuln/detail/cve-2024-5642){: external}, and [CVE-2025-6075](https://nvd.nist.gov/vuln/detail/cve-2025-6075){: external}.
- Updates k8s client libraries from 1.32.8 to 1.32.10. 
- Fixed an issue where the EIT enablement was not working in tainted worker pools. 
- `armada-storage-secret v1.2.74`


### 05 December 2025, Version 2.0 - v2.0.21_301434433
{: #cl-add-ons-vpc-file-csi-driver-v2021_301434433}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/cve-2025-9230){: external}.
- Updates Go to version `1.25.4`.
- Introduces Beta Snapshot support in the VPC File CSI Driver for DP2 and RFS profile-based storage classes.
- Introduces support for default VolumeSnapshotClasses to enhance the user experience when creating snapshots, including ibmc-vpcfile-snapshot-delete and ibmc-vpcfile-snapshot-retain.
- `csi-snapshotter v8.2.1`
- `armada-storage-secret v1.2.71`


### 12 November 2025, Version 2.0 - 2.0.20_296667134
{: #cl-add-ons-vpc-file-csi-driver-2020_296667134}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-58189](https://nvd.nist.gov/vuln/detail/cve-2025-58189){: external}, [CVE-2025-61725](https://nvd.nist.gov/vuln/detail/cve-2025-61725){: external}, [CVE-2025-58185](https://nvd.nist.gov/vuln/detail/cve-2025-58185){: external}, and [CVE-2025-61723](https://nvd.nist.gov/vuln/detail/cve-2025-61723){: external}.
- Updates Go to version `1.25.3`.
- `armada-storage-secret v1.2.70`


### 05 November 2025, Version 2.0 - 2.0.19_294159886
{: #cl-add-ons-vpc-file-csi-driver-2019_294159886}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-5187](https://nvd.nist.gov/vuln/detail/cve-2025-5187){: external}.
- Updates k8s client libraries from 1.32.6 to 1.32.8 
- `armada-storage-secret v1.2.69`


### 22 September 2025, Version 2.0 - 2.0.16_443
{: #cl-add-ons-vpc-file-csi-driver-2016_443}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-8058](https://nvd.nist.gov/vuln/detail/cve-2025-8058){: external}.
- Updates Go to version `1.23.12`.
- {'Adds 3 new storage classes': 'ibmc-vpc-file-regional, ibmc-vpc-file-regional-max-bandwidth, and ibmc-vpc-file-regional-max-bandwidth-sds. These classes are based on VPC regional file share profiles and are available in Beta for allowlisted accounts.'}
- `armada-storage-secret v1.2.66`


### 18 July 2025, Version 2.0 - 2.0.14_403
{: #cl-add-ons-vpc-file-csi-driver-2014_403}

[Default version]{: tag-green}

- Resolves the following CVEs: [CVE-2025-4802](https://nvd.nist.gov/vuln/detail/cve-2025-4802){: external}, [CVE-2025-4673](https://nvd.nist.gov/vuln/detail/cve-2025-4673){: external}, and [CVE-2025-4563](https://nvd.nist.gov/vuln/detail/cve-2025-4563){: external}.
- Updates Go to version `1.23.10`.
- Updates k8s client libraries from 1.32.3 to 1.32.6 
- Updates imagePullPolicy to IfNotPresent for all containers in the deployment. 
- `armada-storage-secret v1.2.64`


### 18 July 2025, Version 2.0 - 2.0.15_431
{: #cl-add-ons-vpc-file-csi-driver-2015_431}

[Default version]{: tag-green}

- Updates Go to version `1.23.11`.
- `armada-storage-secret v1.2.65`


### 16 June 2025, Version 2.0 - 2.0.13_370
{: #cl-add-ons-vpc-file-csi-driver-2013_370}

- Resolves the following CVEs: [CVE-2025-0395](https://nvd.nist.gov/vuln/detail/cve-2025-0395){: external}, [CVE-2025-3576](https://nvd.nist.gov/vuln/detail/cve-2025-3576){: external}, and [CVE-2025-24528](https://nvd.nist.gov/vuln/detail/cve-2025-24528){: external}.
- Updates Go to version `1.23.9`.
- Adds support for users to configure CPU and memory limits and requests for all file containers. 
- Fixes an issue where the provisioner and resizer containers were restarting due to the client rate-limiter. 
- Enables leader-election for csi-resizer. 
- Fixes a warning shown in PVC during volume expansion. 
- Improves error messages. 
- Updates k8s client libraries to 1.32. 
- {'Note': 'Users might see unwanted messages in file-csi-driver-status configmap.'} 


### 19 February 2025, Version 2.0 - 2.0.10_334
{: #cl-add-ons-vpc-file-csi-driver-2010_334}

- Resolves the following CVEs: [CVE-2024-45339](https://nvd.nist.gov/vuln/detail/cve-2024-45339){: external}, and [CVE-2024-45338](https://nvd.nist.gov/vuln/detail/cve-2024-45338){: external}.
- Resiliency improvement to use VPC Storage service API for tagging volumes. This doesn't impact existing or new PVCs. This reduces the number of Kubernetes service API calls. 
- Updates the golang base image to 1.22.12. 
- Updates the armada-storage-secret to v1.2.55. 


## Version 1.2
{: #cl-add-ons-vpc-file-csi-driver-1.2}


### 19 February 2025, Version 1.2 - 1.2.14_332
{: #cl-add-ons-vpc-file-csi-driver-1214_332}

- Resolves the following CVEs: [CVE-2024-45339](https://nvd.nist.gov/vuln/detail/cve-2024-45339){: external}, and [CVE-2024-45338](https://nvd.nist.gov/vuln/detail/cve-2024-45338){: external}.
- Resiliency improvement to use VPC Storage service API for tagging volumes. This doesn't impact existing or new PVCs. This reduces the number of Kubernetes service API calls. 
- Updates the golang base image to 1.22.12. 
- Updates the armada-storage-secret to v1.2.55. 


### 11 December 2024, Version 1.2.13_326
{: #1.2.13_326_is_file_relnote}

- Fixes [CVE-2024-51744](https://nvd.nist.gov/vuln/detail/cve-2024-51744){: external}.
- Updates the `storage-secret-sidecar` image to `v1.2.52`.


### 3 October 2024, Version 1.2.12_312
{: #1.2.12_312_is_file_relnote}

- Updates the golang base image to `1.22.7`.
- Updates to Kubernetes 1.30 client libraries.
- Updates the CSI specification to version `1.9.0`.
- Fixes a security issue for the CSI sidecar liveness probe. The sidecar now runs as non-root in the Node Server pod.
- Updates the following sidecar images: `csi-provisioner:v5.0.2`, `csi-resizer:v1.11.2`, `livenessprobe:v2.13.1`, and `csi-node-driver-registrar:v2.11.1`.
- Resolves [CVE-2024-2398](https://nvd.nist.gov/vuln/detail/cve-2024-2398){: external}, [CVE-2024-37370](https://nvd.nist.gov/vuln/detail/cve-2024-37370){: external}, [CVE-2024-37371](https://nvd.nist.gov/vuln/detail/cve-2024-37371){: external}.


### 15 July 2024, Version 1.2.10_254
{: #1.2.10_254_is_file_relnote}

- Updates the golang image to `1.21.12-community`.
- Updates the `armada-storage-secret` to `v1.2.40`.
- Resolves [CVE-2024-28182](https://nvd.nist.gov/vuln/detail/cve-2024-28182){: external} and [CVE-2023-2953](https://nvd.nist.gov/vuln/detail/cve-2023-2953){: external}.


### 21 June 2024, Version 1.2.9_245
{: #1.2.9_245_is_file_relnote}

- Updates `golang` to `1.21.11-community`.
- Updates the `armada-storage-secret` to `v1.3.8`.
- Resolves: [CVE-2024-26458](https://nvd.nist.gov/vuln/detail/cve-2024-26458){: external}, [CVE-2024-26461](https://nvd.nist.gov/vuln/detail/cve-2024-26461){: external}, [CVE-2024-33600](https://nvd.nist.gov/vuln/detail/cve-2024-33600){: external}, [CVE-2024-33601](https://nvd.nist.gov/vuln/detail/cve-2024-33601){: external}, [CVE-2024-33602](https://nvd.nist.gov/vuln/detail/cve-2024-33602){: external}, [CVE-2024-2961](https://nvd.nist.gov/vuln/detail/cve-2024-33602){: external}, and [CVE-2024-33599](https://nvd.nist.gov/vuln/detail/cve-2024-33599){: external}.


### 10 May 2024, Version 1.2.8_174
{: #1.2.8_174_is_file_relnote}

- Updates `golang` to `1.21.9-community`.
- Removes `curl` package from base image.
- Updates the `armada-storage-secret` to `v1.2.35`.
- Sets `handle-volume-inuse-error` flag to `false` in the `csi-resizer` to reduce costs associated with watching all pods in the cluster which can cause `OOM Killed` errors for the `csi-resizer`.
- Resolves [CVE-2023-46218](https://nvd.nist.gov/vuln/detail/cve-2023-46218){: external}, [CVE-2023-28322](https://nvd.nist.gov/vuln/detail/cve-2023-28322){: external}, and [CVE-2023-38546](https://nvd.nist.gov/vuln/detail/cve-2023-38546){: external}.


### 08 March 2024, Version 1.2.7_154
{: #1.2.7_154_is_file_relnote}

- Base image migrated from UBI to golang.


### 08 February 2024, Version 1.2.6_130
{: #1.2.6_130_is_file_relnote}


- Fixes hanging issue related to mounting and unmounting after node server restart.
- Introduces granular locking mounting and unmounting at the `targetPath` level.
- Disables the CSI NodeExpansion method as it is not required for the file share. The PVC can still be expanded.
- Changes how the IAM endpoint is determined for VPC Gen2 clusters.
- Upgrades Kubernetes client library to 1.28.
- Upgrades CSI spec to 1.8.0.
- Resolves the following CVEs: [CVE-2022-48560](https://nvd.nist.gov/vuln/detail/cve-2022-48560){: external}, [CVE-2022-48564](https://nvd.nist.gov/vuln/detail/cve-2022-48564){: external}, [CVE-2023-39615](https://nvd.nist.gov/vuln/detail/cve-2023-39615){: external}, [CVE-2023-43804](https://nvd.nist.gov/vuln/detail/cve-2023-43804){: external}, [CVE-2023-45803](https://nvd.nist.gov/vuln/detail/cve-2023-45803){: external}, and [CVE-2023-5981](https://nvd.nist.gov/vuln/detail/cve-2023-5981){: external}.
- Updates the following sidecar images: 
    - `armada-storage-secret` to `v1.2.31`.
    - `csi-node-driver-registrar` to `v2.9.3`.
    - `csi-provisioner` to `v3.6.3`.
    - `csi-resizer` to `v1.9.3`.
    - `livenessprobe` to `v2.11.0`.


### 10 January 2024, Version 1.2.5_107
{: #1.2.5_107_is_file_relnote}

- Resolves [CVE-2023-3446](https://nvd.nist.gov/vuln/detail/cve-2023-3446){: external}, [CVE-2023-3817](https://nvd.nist.gov/vuln/detail/cve-2023-3817){: external}, and [CVE-2023-5678](https://nvd.nist.gov/vuln/detail/cve-2023-5678){: external}.
- Applies a security fix to use the correct socket path following SElinux policy module changes and CSI recommendations to use `/var/lib/kubelet/plugins/`.


### 27 November 2023, Version 1.2.3_97
{: #1.2.3_97_is_file_relnote}

- Updates Golang to `1.20.11`.
- Updates UBI image to `8.9.1029`.
- Updates the `armada-storage-secret` to `v1.2.29`.
- Resolves the following CVEs: [CVE-2023-22745](https://nvd.nist.gov/vuln/detail/cve-2023-22745){: external}, [CVE-2007-4559](https://access.redhat.com/security/cve/cve-2007-4559){: external}, [CVE-2023-40217](https://nvd.nist.gov/vuln/detail/cve-2023-40217){: external}, and [CVE-2023-4641](https://nvd.nist.gov/vuln/detail/cve-2023-4641){: external}.


### 31 October 2023, Version version 1.2.0
{: #0120_is_file}


- Tiered and custom profile storage classes are no longer supported. Update your PVCs to use a `dp2` storage classes.
- Adds support for granular authorization via the Virtual Network Interface VNI (Elastic Network Interface ENI).
- Adds support for cross zone mounting by default. Pods can now mount storage volumes across zones.
- Allows you to bring your own security group to control granular authorization at the worker node, zone, or worker pool level.
- Adds bring your own subnet support to control which subnet the virtual network interface (VNI) IP for storage is assigned and created in.
- Adds bring your own IP support existing `PrimaryIP` which the VNI will assign.
- Allows you to set a custom `PrimaryIPAddress` within the subnet range where the VNI IP is assigned and created.


## Version 1.1
{: #011_is_file}


### 27 November 2023, Version 1.1.10_93
{: #1.1.10_93_is_file_relnote}

- Updates Golang to `1.20.11`.
- Updates UBI image to `8.9.1029`.
- Updates the `armada-storage-secret` to `v1.2.29`.
- Resolves the following CVEs: [CVE-2023-22745](https://nvd.nist.gov/vuln/detail/cve-2023-22745){: external}, [CVE-2007-4559](https://access.redhat.com/security/cve/cve-2007-4559){: external}, [CVE-2023-40217](https://nvd.nist.gov/vuln/detail/cve-2023-40217){: external}, and [CVE-2023-4641](https://nvd.nist.gov/vuln/detail/cve-2023-4641){: external}.


### 13 November 2023, Version 1.1.9_87
{: #1.1.9_87_is_file_relnote}

- Updates the `storage-secret-sidecar` image to `1.2.27`.
- Updates Golang to `1.20.10`.
- Resolves [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/cve-2023-44487){: external}, [CVE-2023-4911](https://nvd.nist.gov/vuln/detail/cve-2023-4911){: external}, [CVE-2023-4527](https://nvd.nist.gov/vuln/detail/cve-2023-4527){: external}, [CVE-2023-4806](https://nvd.nist.gov/vuln/detail/cve-2023-4806){: external}, [CVE-2023-4813](https://nvd.nist.gov/vuln/detail/cve-2023-4813){: external}.