GCP Release Notes: October 22, 2025

GCP Release Notes: October 22, 2025

BigQuery

Feature

You can now use custom constraints with Organization Policy to provide more granular control over specific fields for some BigQuery sharing resources. For more information, see Manage Sharing data exchanges and listings using custom constraints. This feature is in preview.

Issue

Support for table parameters in table-value functions (TVFs) has been temporarily disabled. We are working to restore this feature as soon as possible.

Feature

BigQuery ML now offers a built-in TimesFM univariate time series forecasting model that implements Google Research’s open source TimesFM model. You can use BigQuery ML’s built-in TimesFM model with the following functions:

  • Use AI.FORECAST to perform forecasting. This function now supports a larger context window.
  • Use AI.EVALUATE to evaluate forecasted data against a reference time series based on historical data.

To try using a TimesFM model with the AI.FORECAST function, see Forecast a time series with a TimesFM univariate model.

This feature is generally available (GA).

Dataproc

Announcement

Announcing the General Availability (GA) of Lightning Engine for Google Cloud Serverless for Apache Spark. Lightning Engine is a high-performance query accelerator that delivers up to 4.3x faster performance for Spark workloads compared to open-source Spark, as measured on TPC-H-like benchmarks.

For more details on enabling Lightning Engine and its advanced features like Native Query Execution (NQE), see the official documentation.

Changed

Serverless for Apache Spark: With the Lightning Engine GA release, the property to enable Native Query Execution (NQE) feature has been updated.

In order to use Lightning Engine, submit your jobs in the Premium tier. Under Lightning Engine, if you would like to use the NQE feature, set the new flag: spark.dataproc.lightningEngine.runtime=native. Users are encouraged to try this feature to explore the full potential of Lightning Engine.

For backward compatibility, the legacy property that was used to enable NQE spark.dataproc.runtimeEngine=native will continue to be honored in the existing runtimes 1.2, 2.2 and 2.3, but it’s not supported in future releases (3.0+ runtimes).

Google Kubernetes Engine

Changed

(2025-R44) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

Extended channel

No channel

Security

(2025-R44) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.28.15-gke.2793000 cos-113-18244-448-63 cos-113-18244-448-63 release notes
1.29.15-gke.2085000 cos-113-18244-448-63 cos-113-18244-448-63 release notes
1.30.14-gke.1408000 cos-113-18244-448-63 cos-113-18244-448-63 release notes
1.31.13-gke.1123000 cos-117-18613-339-84 cos-117-18613-339-84 release notes
1.32.9-gke.1207000 cos-117-18613-339-84 cos-117-18613-339-84 release notes
1.33.5-gke.1308000 cos-121-18867-199-88 cos-121-18867-199-88 release notes
1.34.0-gke.2201000 cos-121-18867-199-28 cos-121-18867-199-28 release notes
1.34.1-gke.1829001 cos-125-19216-0-94 cos-125-19216-0-94 release notes

Changed

(2025-R44) Version updates

Changed

(2025-R44) Version updates

Changed

(2025-R44) Version updates

Changed

(2025-R44) Version updates

Changed

(2025-R44) Version updates

Google SecOps Marketplace

Feature

SentinelOneV2: Version 42.0

  • The following new actions have been added:

    • Create Device Control Rule

    • Delete Device Control Rule

    • Update Device Control Rule

Changed

CrowdStrike Falcon: Version 67.0

  • Fixed a bug where the Contains filter would fail to find hosts when the Max Hosts To Return limit was applied in the following action:

    • List Host

Changed

CSV: Version 34.0

  • Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:

    • Save Json to CSV

Changed

DomainTools: Version 8.0

  • Extended capabilities in the following action:

    • Get Domain Risk
  • Added support for the domain entity type in the following actions:

    • Get Domain Profile

    • Get Domain Risk

    • Reverse Domain

Google SecOps SIEM

Feature

SentinelOneV2: Version 42.0

  • The following new actions have been added:

    • Create Device Control Rule

    • Delete Device Control Rule

    • Update Device Control Rule

Changed

CrowdStrike Falcon: Version 67.0

  • Fixed a bug where the Contains filter would fail to find hosts when the Max Hosts To Return limit was applied in the following action:

    • List Host

Changed

CSV: Version 34.0

  • Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:

    • Save Json to CSV

Changed

DomainTools: Version 8.0

  • Extended capabilities in the following action:

    • Get Domain Risk
  • Added support for the domain entity type in the following actions:

    • Get Domain Profile

    • Get Domain Risk

    • Reverse Domain

Feature

earliest and latest functions supported in Rules and Dashboards

The earliest and latest YARA-L functions for statistics and aggregations are now supported in Rules and Dashboards, in addition to Search.

For more information, see earliest and latest.

Google SecOps SOAR

Feature

SentinelOneV2: Version 42.0

  • The following new actions have been added:

    • Create Device Control Rule

    • Delete Device Control Rule

    • Update Device Control Rule

Changed

CrowdStrike Falcon: Version 67.0

  • Fixed a bug where the Contains filter would fail to find hosts when the Max Hosts To Return limit was applied in the following action:

    • List Host

Changed

CSV: Version 34.0

  • Fixed a bug that caused inconsistent column order for the same JSON input by stabilizing the order based on the keys of the first object in the list in the following action:

    • Save Json to CSV

Changed

DomainTools: Version 8.0

  • Extended capabilities in the following action:

    • Get Domain Risk
  • Added support for the domain entity type in the following actions:

    • Get Domain Profile

    • Get Domain Risk

    • Reverse Domain

Memorystore for Redis

Feature

We have implemented a security fix for CVE-2025-49844.

Memorystore for Valkey

Feature

We have implemented a security fix for CVE-2025-49844.

Policy Intelligence

Fixed

The issue that caused IAM recommender role recommendations to be inaccurate and out of date is fixed.

reCAPTCHA

Changed

reCAPTCHA Mobile SDK v18.8.1 is available for iOS. This version fixes an issue with iOS 26 screen time showing use from recaptcha.net

Source: Google Cloud Platform

Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *