## robusta-dev/robusta — 0.47.0…0.48.0-alpha

_14 commits._

### Fixes
- **ROB-1207: Bump cryptography to ^50.0.0 to fix CVE-2026-69247 (#2155)** (314f520)
- **Fix CVE-2026-27205: upgrade Flask to ^3.1.3 (#2143)** (2a4b00d)

### Backend
- **Bump Holmes + KRR versions (#2160)** (22e6dc1)
- **Harden Supabase login with retries and timeout configuration (#2159)** (d5f32a2)
- **ROB-889 Stop logging an ERROR for pods whose status is not populated yet (#2139)** (a607284)
- **Security: backport libssh2/attr/acl CVE fixes from Debian forky (#2158)** (5faa7ab)
- **Bump forwarder (kubewatch) image to v2.16.1 to clear 21 CVEs (#2157)** (1d6358e)
- **ROB-997 Bump kubewatch to v2.16.0 (#2156)** (b392d63)
- **Stop interpolating env.RELEASE_VER into shell source (#2149)** (acf0db9)
- **Prevent signing key leakage in email communications (#2148)** (ba198c1)
- **Validate tar members before extracting remote playbook packages (#2144)** (4847afb)
- **ROB-902 - Claude/runner clusterrole privilege 839vtf (#2141)** (153372b)
- **ROB-906 Document the cluster query param across Send Events docs (#2138)** (9ffe7ec)
- **Replace CairoSVG with resvg-py and migrate PDF generation to reportlab (#2136)** (9243468)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/robusta-dev/robusta?utm_source=github-action)._