So Skipper put v0.28.19 on the feed, dated September 28, 2026. We flagged it Important as a security fix. Recency wants the multiarch Docker image line and the short "security fix" opener. Fine. Those are the lines people screenshot when they skim a Go reverse-proxy patch tag.
The line that matters, to the best of my understanding, is the supportListener change. GET /routes (and /routes/{zone}) on the default support listener (:9911) used to serialize every filter argument verbatim with no authentication and no redaction. Inline credentials in routes such as setRequestHeader("Authorization", ...) and oauthOidc* client secrets showed up in the response. GHSA-x6qh-mfgj-wc45 (High) covers that exposure. v0.28.19 redacts security-sensitive data from /routes, and adds an optional Redactable filter interface so filters can return placeholder args via RedactedArgs() instead of the live values. Your AE forwards 0.28.19. A customer whose monitoring scrapes :9911/routes for full filter args starts seeing placeholders. A customer who left the support listener reachable with inline secrets in routes starts asking whether those credentials were ever exposed. That is the product change you track when you sell next to Kubernetes ingress and HTTP routers, not the registry image note.
There is a sibling Important security tag from the same day: v0.28.18 patches GHSA-373c-6ffw-j63p, where blockContent / blockContentHex missed needles that straddle a 32 KiB consumer-read boundary inside the documented 2 MiB buffer. Operators who rely on those filters for content gates (including short needles like ${) need that patch too. Kind of easy to paste both GHSA ids into a status update and sound thorough. Kind of useless when the partner ticket is "our /routes scrape lost the Authorization args" or "blockContent still let a crafted body through."
I keep almost filing Skipper under "ingress proxy bump, ignore." Kind of the wrong habit when you sell into teams that run Zalando Skipper (or forks) as cluster ingress and keep secrets inline in eskip. Tracking product change here means reading past the multiarch bullet and asking which line changes a partner ticket. Let's say the talking point is not "0.28.19 shipped a security fix." It is /routes on the support listener redacts inline secrets now (and you should not expose :9911 unauthenticated anyway), then yes mention v0.28.18 closes the blockContent boundary miss. We pull both tags into a uniform entry shape at /sources/skipper.releases. Same JSON as everything else. Recency still wants the Docker registry line. Recency is not the routes redaction.