A bug in the image streaming feature caused authentication-related failures in specific scenarios when the workload tried to access container image data
## Fix
A bug in the [image streaming](https://cloud.google.com/kubernetes-engine/docs/how-to/image-streaming) feature caused authentication-related failures in specific scenarios when the workload tried to access container image data. This bug has been fixed in the following GKE versions:
* 1.32.0-gke.1448000 and above.
* 1.31.4-gke.1183000 and above.
* 1.30.8-gke.1261000 and above.
## Security
A security vulnerability was discovered in the Google Secret Manager Provider for Secret Store CSI Driver. This vulnerability could allow an attacker to gain access to the Kubernetes service account token of the CSI driver.
For more details, see [GCP-2025-006 security bulletin](https://cloud.google.com/kubernetes-engine/security-bulletins#gcp-2025-006).
## Feature
GKE cluster notifications have the following new capabilities:
* You can now receive cluster notifications through Cloud Logging. To learn more, see [Viewing cluster notifications in Cloud Logging (Preview)](https://cloud.google.com/kubernetes-engine/docs/concepts/cluster-notifications#viewing-logging).
* GKE now sends a cluster notification to notify you when your cluster is running a minor version that is at or near the end of support. To learn more, see [Minor version at or near the end of support](https://cloud.google.com/kubernetes-engine/docs/concepts/cluster-notifications#end-of-standard-support-notification).
* GKE now sends a cluster notification to notify you when your cluster has completed an upgrade operation. To learn more, see [Upgrade operation is complete](https://cloud.google.com/kubernetes-engine/docs/concepts/cluster-notifications#upgrade-operation-complete-notification).
For more details about the different types of cluster notifications GKE sends and how you can receive them, see [Cluster notifications](https://cloud.google.com/kubernetes-engine/docs/concepts/cluster-notifications).
What else is happening at Google Cloud Platform?
Read update
M128 release Except for TensorFlow container images, new container images don't include conda
about 18 hours ago
You can now use the Observability API to set the default log scope
about 21 hours ago
The rollout of managed Cloud Service Mesh version 1.20 to the rapid channel has completed
about 22 hours ago
The rollout of managed Cloud Service Mesh version 1.20 to the rapid channel has completed
about 22 hours ago
GKE cluster versions have been updated. New versions available for upgrades and new clusters
about 23 hours ago