BigQuery
Feature
You can now use custom constraints with Organization Policy to provide more granular control over specific fields for some BigQuery sharing resources. For more information, see Manage Sharing data exchanges and listings using custom constraints. This feature is in preview.
Issue
Support for table parameters in table-value functions (TVFs) has been temporarily disabled. We are working to restore this feature as soon as possible.
Feature
BigQuery ML now offers a built-in TimesFM univariate time series forecasting model that implements Google Research’s open source TimesFM model. You can use BigQuery ML’s built-in TimesFM model with the following functions:
- Use
AI.FORECASTto perform forecasting. This function now supports a larger context window. - Use
AI.EVALUATEto evaluate forecasted data against a reference time series based on historical data.
To try using a TimesFM model with the AI.FORECAST function, see
Forecast a time series with a TimesFM univariate model.
This feature is generally available (GA).
Dataproc
Announcement
Announcing the General Availability (GA) of Lightning Engine for Google Cloud Serverless for Apache Spark. Lightning Engine is a high-performance query accelerator that delivers up to 4.3x faster performance for Spark workloads compared to open-source Spark, as measured on TPC-H-like benchmarks.
For more details on enabling Lightning Engine and its advanced features like Native Query Execution (NQE), see the official documentation.
Changed
Serverless for Apache Spark: With the Lightning Engine GA release, the property to enable Native Query Execution (NQE) feature has been updated.
In order to use Lightning Engine, submit your jobs in the Premium tier. Under Lightning Engine, if you would like to use the NQE feature, set the new flag: spark.dataproc.lightningEngine.runtime=native. Users are encouraged to try this feature to explore the full potential of Lightning Engine.
For backward compatibility, the legacy property that was used to enable NQE spark.dataproc.runtimeEngine=native will continue to be honored in the existing runtimes 1.2, 2.2 and 2.3, but it’s not supported in future releases (3.0+ runtimes).
Google Kubernetes Engine
Changed
(2025-R44) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters.
The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.
Rapid channel
- Version 1.34.0-gke.2201000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.31.13-gke.1023000
- 1.32.9-gke.1108000
- 1.33.5-gke.1162000
- 1.34.1-gke.1293000
- 1.34.1-gke.1431000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1040000
- 1.31 to 1.32.9-gke.1130000
- 1.32 to 1.33.5-gke.1201000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1040000
- 1.32 to 1.32.9-gke.1130000
- 1.33 to 1.33.5-gke.1201000
- 1.34 to 1.34.0-gke.2201000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Regular channel
- Version 1.33.5-gke.1125000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.31.12-gke.1265000
- 1.32.9-gke.1072000
- 1.33.5-gke.1080000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1008000
- 1.31 to 1.32.9-gke.1092000
- 1.32 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Stable channel
- Version 1.33.4-gke.1350000 is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.31.11-gke.1036000
- 1.32.8-gke.1170000
- 1.33.4-gke.1245000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.12-gke.1220000
- 1.31 to 1.32.9-gke.1010000
- 1.32 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.12-gke.1220000
- 1.32 to 1.32.9-gke.1010000
- 1.33 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Extended channel
- Version 1.33.5-gke.1125000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.28.15-gke.2730000
- 1.28.15-gke.2767000
- 1.29.15-gke.1971000
- 1.29.15-gke.2002000
- 1.30.14-gke.1150000
- 1.30.14-gke.1349000
- 1.31.12-gke.1265000
- 1.32.9-gke.1072000
- 1.33.5-gke.1080000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.27 to 1.28.15-gke.2740000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.28 to 1.28.15-gke.2740000
- 1.29 to 1.29.15-gke.1979000
- 1.30 to 1.30.14-gke.1267000
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
No channel
- Version 1.33.5-gke.1125000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.31.11-gke.1036000
- 1.32.8-gke.1170000
- 1.33.4-gke.1172000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1008000
- 1.31 to 1.32.9-gke.1092000
- 1.32 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Security
(2025-R44) Security updates
This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.
To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:
| GKE version | Container-Optimized OS version | Details |
|---|---|---|
| 1.28.15-gke.2793000 | cos-113-18244-448-63 | cos-113-18244-448-63 release notes |
| 1.29.15-gke.2085000 | cos-113-18244-448-63 | cos-113-18244-448-63 release notes |
| 1.30.14-gke.1408000 | cos-113-18244-448-63 | cos-113-18244-448-63 release notes |
| 1.31.13-gke.1123000 | cos-117-18613-339-84 | cos-117-18613-339-84 release notes |
| 1.32.9-gke.1207000 | cos-117-18613-339-84 | cos-117-18613-339-84 release notes |
| 1.33.5-gke.1308000 | cos-121-18867-199-88 | cos-121-18867-199-88 release notes |
| 1.34.0-gke.2201000 | cos-121-18867-199-28 | cos-121-18867-199-28 release notes |
| 1.34.1-gke.1829001 | cos-125-19216-0-94 | cos-125-19216-0-94 release notes |
Changed
(2025-R44) Version updates
- Version 1.33.5-gke.1125000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.28.15-gke.2730000
- 1.28.15-gke.2767000
- 1.29.15-gke.1971000
- 1.29.15-gke.2002000
- 1.30.14-gke.1150000
- 1.30.14-gke.1349000
- 1.31.12-gke.1265000
- 1.32.9-gke.1072000
- 1.33.5-gke.1080000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.27 to 1.28.15-gke.2740000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.28 to 1.28.15-gke.2740000
- 1.29 to 1.29.15-gke.1979000
- 1.30 to 1.30.14-gke.1267000
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Changed
(2025-R44) Version updates
- Version 1.33.5-gke.1125000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.31.11-gke.1036000
- 1.32.8-gke.1170000
- 1.33.4-gke.1172000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1008000
- 1.31 to 1.32.9-gke.1092000
- 1.32 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Changed
(2025-R44) Version updates
- Version 1.34.0-gke.2201000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.31.13-gke.1023000
- 1.32.9-gke.1108000
- 1.33.5-gke.1162000
- 1.34.1-gke.1293000
- 1.34.1-gke.1431000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1040000
- 1.31 to 1.32.9-gke.1130000
- 1.32 to 1.33.5-gke.1201000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1040000
- 1.32 to 1.32.9-gke.1130000
- 1.33 to 1.33.5-gke.1201000
- 1.34 to 1.34.0-gke.2201000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Changed
(2025-R44) Version updates
- Version 1.33.5-gke.1125000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.31.12-gke.1265000
- 1.32.9-gke.1072000
- 1.33.5-gke.1080000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.13-gke.1008000
- 1.31 to 1.32.9-gke.1092000
- 1.32 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.13-gke.1008000
- 1.32 to 1.32.9-gke.1092000
- 1.33 to 1.33.5-gke.1125000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Changed
(2025-R44) Version updates
- Version 1.33.4-gke.1350000 is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.31.11-gke.1036000
- 1.32.8-gke.1170000
- 1.33.4-gke.1245000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.30 to 1.31.12-gke.1220000
- 1.31 to 1.32.9-gke.1010000
- 1.32 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.31 to 1.31.12-gke.1220000
- 1.32 to 1.32.9-gke.1010000
- 1.33 to 1.33.4-gke.1350000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Google SecOps Marketplace
Feature
SentinelOneV2: Version 42.0
The following new actions have been added:
Create Device Control Rule
Delete Device Control Rule
Update Device Control Rule
Changed
CrowdStrike Falcon: Version 67.0
Fixed a bug where the Contains filter would fail to find hosts when the
Max Hosts To Returnlimit was applied in the following action:- List Host
Changed
CSV: Version 34.0
Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:
- Save Json to CSV
Changed
DomainTools: Version 8.0
Extended capabilities in the following action:
- Get Domain Risk
Added support for the domain entity type in the following actions:
Get Domain Profile
Get Domain Risk
Reverse Domain
Google SecOps SIEM
Feature
SentinelOneV2: Version 42.0
The following new actions have been added:
Create Device Control Rule
Delete Device Control Rule
Update Device Control Rule
Changed
CrowdStrike Falcon: Version 67.0
Fixed a bug where the Contains filter would fail to find hosts when the
Max Hosts To Returnlimit was applied in the following action:- List Host
Changed
CSV: Version 34.0
Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:
- Save Json to CSV
Changed
DomainTools: Version 8.0
Extended capabilities in the following action:
- Get Domain Risk
Added support for the domain entity type in the following actions:
Get Domain Profile
Get Domain Risk
Reverse Domain
Feature
earliest and latest functions supported in Rules and Dashboards
The earliest and latest YARA-L functions for statistics and aggregations
are now supported in Rules and Dashboards, in addition to Search.
For more information, see earliest and latest.
Google SecOps SOAR
Feature
SentinelOneV2: Version 42.0
The following new actions have been added:
Create Device Control Rule
Delete Device Control Rule
Update Device Control Rule
Changed
CrowdStrike Falcon: Version 67.0
Fixed a bug where the Contains filter would fail to find hosts when the
Max Hosts To Returnlimit was applied in the following action:- List Host
Changed
CSV: Version 34.0
Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:
- Save Json to CSV
Changed
DomainTools: Version 8.0
Extended capabilities in the following action:
- Get Domain Risk
Added support for the domain entity type in the following actions:
Get Domain Profile
Get Domain Risk
Reverse Domain
Memorystore for Redis
Feature
We have implemented a security fix for CVE-2025-49844.
Memorystore for Valkey
Feature
We have implemented a security fix for CVE-2025-49844.
Policy Intelligence
Fixed
The issue that caused IAM recommender role recommendations to be inaccurate and out of date is fixed.
reCAPTCHA
Changed
reCAPTCHA Mobile SDK v18.8.1 is available for iOS. This version fixes an issue with iOS 26 screen time showing use from recaptcha.net
Source: Google Cloud Platform




