The week in one paragraph
157 notes across 38 products and five days, down from 217, and for the third time in four weeks the security bulletins feed produced nothing in the window — the CVE work this week arrives inside product release notes instead. Only two notes carry a Breaking tag and both are Looker. But the week is more interesting than the count suggests for anyone who has been following the identity material: IAM shipped session revocation for federated users, GKE retired an identity feature and named Workforce Identity Federation as the migration target, and the VPC Service Controls violation analyzer learned to propose fixes rather than only explain denials. Three notes, one theme — the federated-identity story filling in.
Session revocation for federated users goes GA
The item of the week is one line in the IAM release notes: revoking active sessions and short-lived credentials for Workforce Identity Federation users (principals) across all clients is generally available. And it is operable rather than console-only — you can revoke workforce user sessions by using the gcloud CLI or the REST API.
This matters because it closes a specific gap. Workforce Identity Federation lets an external identity provider stand behind Google Cloud access, which is excellent until you need somebody out now: the credential already issued is short-lived but live, and removing the upstream identity does not reach into a session that has already started. Revocation across all clients, driven from an API, is the control that was missing.
Two of this series’ architecture posts landed on the same complaint from different directions. #47 found that a service account access token cannot be revoked and you wait for expiry. #52 measured the propagation table and found that removing somebody from a group is the slowest direction of the slowest method — typically several minutes, potentially hours. Against that, a documented API that revokes active sessions and short-lived credentials for a federated principal across all clients is a genuinely better answer to the dismissal case than anything in those posts. It is scoped to Workforce Identity Federation rather than everything, so it does not retire the propagation problem — but for the population it covers, it is the fast path that was absent.
A three-week shutdown, and a GKE identity feature retired
The shortest runway in the week comes from Security Command Center: Artifact guard with CI/CD integration is deprecated. It will be shut down on October 30, 2026. That is a deprecation and a shutdown date announced together, roughly three weeks out. Most deprecations in these roundups run to 2027 or 2028; this one does not, so if anything in your build pipeline depends on it, this is the note to act on rather than file.
The longer-dated one is more consequential architecturally. Starting on July 1, 2026, Identity Service for GKE is deprecated in GKE version 1.36 and earlier, and this feature is also unavailable in organizations that were created on or after July 1, 2025. The instruction is specific: before you upgrade clusters to 1.37 and later, disable this feature and migrate to Workforce Identity Federation.
Read the ordering carefully, because it is the part that bites. The feature is not supported in 1.37 and later, and the migration is a prerequisite of the upgrade rather than a follow-up to it. A cluster upgrade is usually treated as a routine version bump; here it is gated on an identity migration, and discovering that during an upgrade window is the expensive way to learn it. Note also the second sentence: organisations created on or after 1 July 2025 never had the feature, so this is an item that only affects older estates — which are exactly the estates least likely to be reading GKE release notes closely.
The perimeter analyzer learns to suggest fixes
In Preview, and directly relevant to anyone who has spent an afternoon on a perimeter denial: support for automated remediation suggestions is available in the VPC Service Controls violation analyzer. The description is more ambitious than "here is the rule that blocked you" — remediation suggestions analyze access denial events and generate actionable, narrowly scoped configuration changes to resolve perimeter denials and adhere to the principle of least privilege.
What it will propose is enumerated: the remediation engine can automatically propose ingress rules, egress rules, VPC accessible services updates, and existing or new context-aware access levels. The phrase worth holding onto is "narrowly scoped", because the instinctive fix for a perimeter denial is a wide ingress rule that makes the error go away, and a tool that proposes the narrow version instead is doing the part people skip.
One caution that is mine rather than Google’s: a suggestion that may create a new context-aware access level is a suggestion that edits the conditions layer. Access levels bound to a binding are ORed together, so an added level widens rather than narrows the overall grant even when the level itself is tight. The suggestions are a good starting point; the review still belongs to a person who knows which levels are already attached.
Platform, data and the rest
Looker 26.20 supplies both of the week’s Breaking notes, and both are the kind that break something quietly. Custom TopoJSON URL validation is updated to improve security — a good change, with the consequence that existing dashboards and Looks with the Google Maps Enhancements preview feature enabled that use custom TopoJSON files may be impacted. Separately, a permissions change: when you set up a connection, self-service modeling will now be available only if a role that grants create_self_service_from_table also selects it through that role’s model set. The deployment is dated — expected deployment start: Monday, October 12, 2026 — so there are two days to check dashboards before it begins.
With no numbered security bulletins, the CVE work sits in product notes. Container Optimized OS shipped across several milestones with the same two fixes each time: fixed CVE-2026-5928 in sys-libs/glibc and upgraded dev-libs/libxml2 to v2.15.4. This fixes CVE-2026-86140. Those repeat per release and are rolled up in the inventory rather than listed once per milestone. Apigee shipped security fixes for apigee-asm-ingress covering several CVEs including CVE-2026-33818, and GKE’s 2026-R43 release carried cumulative COS image updates, with version 1.36.4-gke.2046002 is now the default version for cluster creation in the Rapid channel.
Two smaller changes worth a note because they alter a default. Memorystore for Redis: RDB snapshots are enabled by default when you create an instance using the Google Cloud console, generally available — a safer default that will also show up as storage you did not previously pay for. And in BigQuery, Iceberg external tables and Iceberg managed tables now support flexible column names by default, alongside a packaging change where the BigQuery JupyterLab plugin is now enabled independently of the Dataproc plugin.
What I would act on
- Wire the Workforce session revocation API into your offboarding runbook. It is GA, it is scriptable from gcloud or REST, and it is the fastest revocation path now available for federated principals. If your leaver process currently ends at the identity provider, it stops short of the live session.
- Check whether anything uses Artifact guard with CI/CD integration, today. Shutdown is 30 October 2026. Three weeks is enough time to migrate and not enough to discover it late.
- If you run GKE 1.36 or earlier with Identity Service for GKE, schedule the migration before the upgrade. It is unsupported from 1.37, and the documented order is disable and migrate to Workforce Identity Federation first. Older organisations only — anything created from July 2025 never had it.
- Look at Looker dashboards using custom TopoJSON before Monday. Deployment starts 12 October and the note says existing dashboards may be impacted.
- Try the VPC Service Controls remediation suggestions on a denial you already understand. It is Preview, so calibrate it against a case where you know the right answer before trusting it on one where you do not.
Complete inventory — all 157 notes
How this inventory reconciles
Google Cloud published 157 notes across 38 products and 5 days in this window, read from 4 feeds. Every one of them is accounted for below, in exactly one place:
| Bucket | Notes | Why |
|---|---|---|
| Listed individually | 133 | Every note that is its own distinct fact. |
| Published under several products | 4 | 2 texts issued once per runtime or service; shown once, with the products named. |
| Repeating runs, rolled up | 20 | 1 product/type run where the same text recurs once per release. Summarised with the full identifier list, not deduplicated. |
| Total | 157 |
Repeating runs, rolled up
- Container Optimized OS (20 notes) — Fixed20 notes, across 3 releases (cos-121-18867-624-8, cos-125-19216-700-23, cos-129-19506-505-25). 11 distinct texts, each repeated once per release and counted individually:
- Added support for NVIDIA driver v595.91.07.
- Added support for net-fs/lustre-client-drivers v2.14.0_p262.
- Added the "watchdog_timeout" module parameter to the idpf driver.
- Rebuilt Go binaries with Go 1.25.14.
- Updated app-admin/google-guest-configs to v20260928.00.
- Upgraded app-admin/google-guest-configs to v20260928.00.
- Upgraded app-admin/oslogin to v20260924.00.
- Upgraded dev-libs/expat to v2.8.5.
- Upgraded sys-apps/xemu to v0.0.11.
- Upgraded sys-libs/timezone-data to v2026e.
- Upgraded sys-process/lsof to v4.99.7.
One change, published under several products
- FixedThe following issues were fixed in 1.36.100-gke.144: Link to Vulnerability fixes for the list of security vulnerabilities addressed in this release. Fixed an is…Published under 2 products: Google Distributed Cloud (software only) for VMware, Google Distributed Cloud (software only) for bare metal.
- FeaturePreview : External IPv6 addresses are now supported for Standard Tier . For more information, see IPv6 subnet ranges .Published under 2 products: Compute Engine, Virtual Private Cloud.
Everything else, by product
AI Hypercomputer — 1
- FeatureGenerally available : When you reserve compute resources for creating GPU instances through your account team, you can include a Hyperdisk pool in the same requ…Tue 06 Oct
Agent Platform Workbench — 5
- Change20261004.00_p0 ReleaseMon 05 Oct · 20261004.00_p0
- ChangeInstalled latest packages from upstream dependencies.Mon 05 Oct · 20261004.00_p0
- ChangeThe BigQuery JupyterLab plugin is now enabled independently of the Dataproc plugin: it is enabled by default and can be turned off with the new disable-bigquery…Mon 05 Oct · 20261004.00_p0
- Change20261004.00_p0 ReleaseMon 05 Oct · 20261004.00_p0
- ChangeInstalled latest packages from upstream dependencies.Mon 05 Oct · 20261004.00_p0
Anti Money Laundering AI — 1
- AnnouncementNew minor engine version released for the commercial line of business within the v004.005 version line ( aml-commercial.default.v004.005.202609-000 ). This vers…Wed 07 Oct
Apigee hybrid — 3
- Announcementv1.14.9 On October 7, 2026 we released an updated version of the Apigee hybrid software, v1.14.9. For information on upgrading, see Upgrading Apigee hybrid to v…Wed 07 Oct · v1.14.9
- FixedFixed in this release Bug ID Description 565072374 Fixed an issue where VerifyJWT policies using a JWKS uriRef could return steps.jwt.NoMatchingPublicKey on the…Wed 07 Oct · v1.14.9
- SecurityBug ID Description N/A Security fixes for apigee-asm-ingress . This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-56853 CVE-20…Wed 07 Oct · v1.14.9
App Optimize API — 1
- FeatureThe App Optimize API remote MCP server is in Preview . For more information see Use the App Optimize API remote MCP server .Wed 07 Oct
BigQuery — 4
- FeatureIceberg external tables and Iceberg managed tables now support flexible column names by default. This feature is generally available (GA).Mon 05 Oct
- FeatureThe gemini-embedding-2 model works well for embedding long strings, including multilingual and unstructured data. It supports a mix of text, images, audio, vide…Mon 05 Oct
- FeatureConversational analytics in BigQuery now supports the AI.CAUSAL_EFFECT function to quantify the impact of specific interventions on time series data. This featu…Tue 06 Oct
- FeatureThe BigQuery Data Engineering Agent is now available in the asia-northeast1 (Tokyo) regional endpoint and supports the gemini-3.5-flash model. For more informat…Fri 09 Oct
Blog — 13
- PostIntroducing Google Cloud Modernize, transforming for (and with) AIMon 05 Oct
- PostAnnouncing MCP Toolbox Java SDK v1.0: Agentic data access for the enterpriseTue 06 Oct
- PostManaged Apache Iceberg at scale: How Spanner powers Lakehouse runtime catalogTue 06 Oct
- PostNetworking for AI inference model serving - GKE only and for all other backendsTue 06 Oct
- PostWhere mission meets moonshot: Join us at the Google Public Sector Summit 2026Tue 06 Oct
- PostAlloyDB: A unified database engine for hybrid searchTue 06 Oct
- PostIntroducing Google Cloud’s U4 compute: Enabling ultra-low latency tradingWed 07 Oct
- PostGoogle Public Sector and SUNY launch AI-enabled platform to accelerate university researchThu 08 Oct
- PostWelcome to Gemini at Work 2026: Introducing the Gemini agentThu 08 Oct
- PostInnovation in Ireland: How Irish brands scale with Gemini EnterpriseThu 08 Oct
- PostEmpowering SMBs to do more with GeminiThu 08 Oct
- PostWhat’s new with Google Data CloudFri 09 Oct
- PostModernizing Unstructured Data Workflows: Alteryx Live Query meets Google Cloud BigQueryFri 09 Oct
Cloud Load Balancing — 1
- FeatureExternal IPv6 addresses are now supported for Standard Tier . For more information, see IPv6 subnet ranges . This feature is in Preview .Mon 05 Oct
Cloud Monitoring — 1
- FeatureBulk registration of discovered services and workloads to an App Hub application is generally available (GA) . For more information, see Register one or more di…Tue 06 Oct
Cloud Run — 1
- FeatureSSH for Cloud Run services and instances is in Preview . Use this feature to establish a secure, interactive shell connection to your running instances.Wed 07 Oct
Cloud SQL for MySQL — 4
- ChangeCloud SQL for MySQL now supports up to 100,000 concurrent connections for Private Service Connect enabled instances created on or after September 30, 2026 with…Tue 06 Oct
- FeatureCloud SQL for MySQL now supports the innodb_cloudsql_managed_buffer_pool_tuneup_pct database flag. Managed buffer pool automatically adjusts the InnoDB buffer p…Thu 08 Oct
- FeatureCloud SQL for MySQL supports blue-green deployments ( Preview ). Blue-green deployments let you update databases—such as performing major version upgrades from…Thu 08 Oct
- FeatureWhen you enable Knowledge Catalog (formerly Dataplex Universal Catalog) integration on an eligible Cloud SQL for MySQL instance created before April 18, 2026 wh…Fri 09 Oct
Cloud SQL for PostgreSQL — 2
- ChangeCloud SQL for PostgreSQL now supports up to 129,024 concurrent connections for Private Service Connect enabled instances created on or after September 30, 2026…Tue 06 Oct
- FeatureWhen you enable Knowledge Catalog (formerly Dataplex Universal Catalog) integration on an eligible Cloud SQL for PostgreSQL instance created before April 18, 20…Fri 09 Oct
Compute Engine — 3
- FeatureGenerally available : Z3 machine types that have 8 to 44 vCPUs can use Hyperdisk Balanced High Availability volumes to synchronously replicate data across two z…Mon 05 Oct
- FeatureGenerally available : When you reserve compute resources for H4D instances through your account team, you can include a Hyperdisk pool in the same request or in…Tue 06 Oct
- FeatureGenerally available : You can sync a Compute Engine VM's clock with its host server's clock by using chrony and ptp_kvm to achieve accuracy designed to be withi…Thu 08 Oct
Confidential Space — 1
- AnnouncementA new Confidential Space image (260900) is available.Mon 05 Oct
Container Optimized OS — 15
- Changecos-133-19999-44-106 Kernel Docker Containerd GPU Drivers COS-6.18.53 v29.4.3 v2.4.1 See ListTue 06 Oct · cos-133-19999-44-106
- Changecos-129-19506-505-25 Kernel Docker Containerd GPU Drivers COS-6.12.110 v27.5.1 v2.2.7 See ListTue 06 Oct · cos-129-19506-505-25
- ChangeUpdated default cos-gpu-installer version to v2.7.9. It installs ucodes firmwares for VR200.Tue 06 Oct · cos-129-19506-505-25
- ChangeUpdated dev-libs/openssl to v3.5.9.Tue 06 Oct · cos-129-19506-505-25
- ChangeRuntime sysctl changes: Changed: kernel.threads-max: 63443 -> 63444 Changed: net.ipv4.udp_mem: 187941 250590 375882 -> 187941 250591 375882 Changed: user.max_cg…Tue 06 Oct · cos-129-19506-505-25
- Changecos-125-19216-700-23 Kernel Docker Containerd GPU Drivers COS-6.12.110 v27.5.1 v2.2.7 See ListTue 06 Oct · cos-125-19216-700-23
- ChangeUpdated dev-libs/openssl to v3.5.9.Tue 06 Oct · cos-125-19216-700-23
- ChangeRuntime sysctl changes: Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068Tue 06 Oct · cos-125-19216-700-23
- Changecos-121-18867-624-8 Kernel Docker Containerd GPU Drivers COS-6.6.157 v27.5.1 v2.0.10 See ListTue 06 Oct · cos-121-18867-624-8
- ChangeEnsure time sync prior to TLS handshake.Tue 06 Oct · cos-121-18867-624-8
- SecurityFixed CVE-2026-5928 in sys-libs/glibc.Tue 06 Oct · cos-129-19506-505-25
- SecurityUpgraded dev-libs/libxml2 to v2.15.4. This fixes CVE-2026-86140.Tue 06 Oct · cos-129-19506-505-25
- SecurityFixed CVE-2026-5928 in sys-libs/glibc.Tue 06 Oct · cos-125-19216-700-23
- SecurityUpgraded dev-libs/libxml2 to v2.15.4. This fixes CVE-2026-86140.Tue 06 Oct · cos-125-19216-700-23
- SecurityUpgraded dev-libs/libxml2 to v2.15.4. This fixes CVE-2026-86140.Tue 06 Oct · cos-121-18867-624-8
Datastream — 1
- FeatureDatastream now supports replicating SQL Server GEOMETRY and GEOGRAPHY spatial data types. For more information, see the following: Map SQL Server data types to…Fri 09 Oct
Gemini — 2
- AnnouncementSale of Gemini Code Assist subscriptions is ending. Starting October 9, 2026, new Gemini Code Assist Standard and Enterprise subscriptions can no longer be purc…Fri 09 Oct
- AnnouncementSale of Gemini Code Assist subscriptions is ending. Starting October 9, 2026, new Gemini Code Assist Standard and Enterprise subscriptions can no longer be purc…Fri 09 Oct
Gemini Enterprise — 4
- FeatureGemini Enterprise: Control access to Antigravity features Administrators can control whether users in their organization have access to the following Google Ant…Tue 06 Oct
- FeatureGemini Enterprise: Pay-as-you-go usage above quota enabled for Frontline, EDU, and Emerging Market editions You can enable pay-as-you-go usage above quota for a…Wed 07 Oct
- FeatureGemini Enterprise: Gemini 3.8 Flash regional availability in Singapore Gemini 3.8 Flash is generally available (GA) in Singapore ( sg ) with in-region at-rest d…Thu 08 Oct
- FeatureGemini Enterprise: Anthropic Claude Opus 5.5 and Claude Sonnet 5.5 in AI developer tools Administrators can enable Anthropic Claude Opus 5.5 ( claude-opus-5-5 )…Thu 08 Oct
Gemini Enterprise Agent Platform — 4
- FixedCodeMender updates (v0.12.0) This release introduces updates to CodeMender: Hidden file scanning : Added the --include-hidden flag to cm find (or include_hidden…Mon 05 Oct
- FeatureGemini Nano Banana 2.1 Gemini Nano Banana 2.1 ( gemini-nano-banana-2.1 ) is available in General Availability (GA) . Gemini Nano Banana 2.1 is optimized for hig…Tue 06 Oct
- FeatureAnthropic's Claude Haiku 5.5 Claude Haiku 5.5 is available in Model Garden.Wed 07 Oct
- FixedCodeMender updates (v0.13.0) This release introduces updates to CodeMender: Consistent finding deduplication : Improved finding deduplication consistency across…Wed 07 Oct
Google Cloud Contact Center as a Service — 2
- AnnouncementGoogle Cloud CCaaS 6.19 We've released version 6.19 of Google Cloud CCaaS. The timing of the update to your instance depends on the deployment schedule that you…Thu 08 Oct
- FixedThis release addresses the following issues: Fixed an issue where agents could be assigned more concurrent chats than their configured maximum limit when multip…Thu 08 Oct
Google Cloud Managed Service for Apache Kafka — 1
- ChangeThe format for bootstrap addresses and broker URLs has changed for new Managed Service for Apache Kafka clusters. To learn how to get a cluster's bootstrap addr…Fri 09 Oct
Google Distributed Cloud (software only) for VMware — 1
- AnnouncementGoogle Distributed Cloud (software only) for VMware 1.36.100-gke.144 is now available for download. To upgrade, see Upgrade a cluster . Google Distributed Cloud…Wed 07 Oct
Google Distributed Cloud (software only) for bare metal — 2
- AnnouncementGoogle Distributed Cloud (software only) for bare metal 1.36.100-gke.144 is now available for download. To upgrade, see Upgrade clusters . Google Distributed Cl…Wed 07 Oct
- FeatureThe following changes were added in 1.36.100-gke.144: Extended the validity period for new certificates generated for GKE Identity Service from 5 years to 10 ye…Wed 07 Oct
Google Kubernetes Engine — 16
- DeprecatedStarting on July 1, 2026, Identity Service for GKE is deprecated in GKE version 1.36 and earlier. This feature is also unavailable in organizations that were cr…Mon 05 Oct
- FeatureGKE support for using the c4-standard-* machine types (up to 192 vCPUs) as Confidential GKE Nodes with Intel TDX is generally available. For more information, s…Mon 05 Oct
- IssueStarting with GKE version 1.36, the default engine for kube-dns is CoreDNS . For Pod IP DNS queries in the <a-b-c-d>.<namespace>.pod.cluster.local format, CoreD…Tue 06 Oct
- FeatureThe microVM sandbox type is now Generally Available (GA) with GKE Sandbox in clusters that run version 1.37.0-gke.4713000 and later. MicroVM sandboxes provide h…Wed 07 Oct
- Change(2026-R43) Version updates GKE cluster versions have been updated. New versions available for upgrades and new clusters. The following versions are now availabl…Thu 08 Oct
- Change(2026-R43) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Thu 08 Oct
- Change(2026-R43) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Thu 08 Oct
- Change(2026-R43) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Thu 08 Oct
- Change(2026-R43) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Thu 08 Oct
- Change(2026-R43) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Thu 08 Oct
- Extended channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Thu 08 Oct
- No channel (deprecated)Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Thu 08 Oct
- Rapid channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Thu 08 Oct
- Regular channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Thu 08 Oct
- Security(2026-R43) Security updates This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorpor…Thu 08 Oct
- Stable channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Thu 08 Oct
Google SecOps — 1
- Feature[Spotlight Feature] Terraform and client libraries for multiple features using Chronicle API Terraform providers and Google Cloud client libraries are now avail…Mon 05 Oct
Google SecOps Marketplace — 2
- ChangeGoogle Chronicle : Version 97.0 Updated the alert synchronization logic in the following job: Google Chronicle Sync JobWed 07 Oct
- ChangeGitsync : Version 53.0 (REGRESSIVE) Updated to support the latest Chronicle API. Important: Existing users must migrate their repository branch and re-export th…Wed 07 Oct
Guest Environment — 2
- FeatureVersion 20260921.00 of the guest agent is now available for all supported operating systems. This version introduces the following features: The managed workloa…Mon 05 Oct
- FixedVersion 20260921.00 of the guest agent is now available for all supported operating systems. This version introduces the following fixes: The NetworkManager set…Mon 05 Oct
Identity and Access Management — 1
- FeatureRevoking active sessions and short-lived credentials for Workforce Identity Federation users (principals) across all clients is generally available . You can re…Tue 06 Oct
Knowledge Catalog — 1
- FeatureData products in Knowledge Catalog now support Looker (Google Cloud core) assets. You can package, govern, and share Looker (Google Cloud core) dashboards, dash…Mon 05 Oct
Looker — 27
- AnnouncementLooker 26.20 will roll out to Looker (original) and Looker (Google Cloud core) instances on the following schedule: Expected deployment start: Monday, October 1…Thu 08 Oct
- BreakingCustom TopoJSON URL validation is updated to improve security. This change is isolated to Google Maps rendering in preview. Existing dashboards and Looks with t…Thu 08 Oct
- BreakingWhen you set up a connection, self-service modeling will now be available only if a role that grants create_self_service_from_table also selects it through that…Thu 08 Oct
- FeatureYou can now apply themes to Looks in addition to internal dashboards.Thu 08 Oct
- FixedAn issue has been fixed where duplicating a scheduled plan could fail to retain the custom message value. This feature now performs as expected.Thu 08 Oct
- FixedTable visualizations now proportionally scale left-pinned columns during automatic sizing, which prevents unnecessary horizontal scrollbars. This feature now pe…Thu 08 Oct
- FixedAn issue has been fixed where enabling subtotals on table visualizations did not automatically disable the Cell Visualizations option. This feature now performs…Thu 08 Oct
- FixedAn issue has been fixed where previews for Looker charts in Slack integrations could fail to be displayed. This feature now performs as expected.Thu 08 Oct
- FixedAn issue has been fixed where editing and saving a dashboard could cause the dashboard to reload indefinitely, forcing users to refresh the page. This feature n…Thu 08 Oct
- FixedAn issue has been fixed where table cell visualizations that included both positive and negative values could display unwanted scrollbars and hide value labels.…Thu 08 Oct
- FixedAn issue has been fixed where the BigQuery JDBC driver could fail to properly parse certain data types, such as BYTES , STRUCT/RECORD , and nested ARRAY structu…Thu 08 Oct
- FixedAn issue has been fixed where linked filters on a dashboard could fail to display autocomplete suggestions even when a parent filter is selected. This feature n…Thu 08 Oct
- FixedThe System Activity query_metrics Explore has been updated to ensure that phase timings (such as connection acquisitions, execution runtimes, and optimistic piv…Thu 08 Oct
- FixedThe System Activity Dashboard Diagnostics dashboard has been updated to fully support statistics, tile run counts, and performance recommendations for LookML da…Thu 08 Oct
- FixedAn issue has been fixed where the color palette popover in visualization settings failed to dynamically reposition when it expanded, causing controls to overlap…Thu 08 Oct
- FixedThe opacity for the comparison bar in short KPI visualizations has been reduced to increase legibility.Thu 08 Oct
- AnnouncementBeginning October 5, 2026, the following features will be automatically enabled for Looker (original) instances running Looker 26.18. Feature enablement for Loo…Fri 09 Oct
- ChangeIn Conversational Analytics, the default question mode is now Fast rather than Thinking . Fast mode is intended for answering quickly, and it directly maps your…Fri 09 Oct
- ChangeThe Modern User Interface preview feature toggle now defaults to ON .Fri 09 Oct
- ChangeThe Modern visualization theme now supports map charts (static map points and regions), word cloud charts, and donut multiples. While support for donut multiple…Fri 09 Oct
- FeatureLooker now includes built-in support for the Dremio 26.0+ (Arrow Flight SQL) dialect. The Dremio 26.0+ (Arrow Flight SQL) uses the bundled Apache Arrow Flight S…Fri 09 Oct
- FeatureThe AI-Assisted Quick Starts feature, called Starter questions in the new Explore experience, is now generally available.Fri 09 Oct
- FeatureThe new Diagnose & Repair tool evaluates your LookML project repository across eight diagnostic test checks in either your personal development environment or t…Fri 09 Oct
- FeatureLooker Continuous Integration (CI) now includes the Style Validator , which enforces LookML coding standards, naming conventions, and structural best practices…Fri 09 Oct
- FeatureNow available in preview , Conversational Analytics agentic workflows support scheduled agentic workflows in addition to triggered agentic workflows . You can u…Fri 09 Oct
- FeatureNow available in preview, Looker Data Apps are freeform canvas dashboards that are built by local AI coding agents, such as Gemini CLI, Claude Code, or Cursor,…Fri 09 Oct
- FeatureLooker now supports connections to the ClickHouse 26+ dialect. ClickHouse 26+ uses modernized JDBC drivers and introduces support for symmetric aggregates . See…Fri 09 Oct
Managed Service for Apache Spark — 1
- ChangeManaged Service for Apache Spark (formerly Google Cloud Serverless for Apache Spark): Users may now specify short template names when creating a serverless sess…Mon 05 Oct
Memorystore for Redis — 1
- FeatureTo help protect your data and provide a baseline level of persistence, RDB snapshots are enabled by default when you create an instance using the Google Cloud c…Thu 08 Oct
Model Armor — 1
- FeatureModel Armor includes enhanced prompt injection and jailbreak protection for Workspace data. This capability improves detection accuracy and minimizes false posi…Fri 09 Oct
Network Intelligence Center — 1
- FeatureFlow Analyzer displays packet drops, allowing you to analyze packet loss in your traffic flows. For more information, see Display flows in packet drop mode .Mon 05 Oct
Network Service Tiers — 1
- FeatureExternal IPv6 addresses are now supported for Standard Tier in Preview . For more information, see IPv6 subnet ranges .Mon 05 Oct
Security Command Center — 2
- DeprecatedArtifact guard with CI/CD integration is deprecated. It will be shut down on October 30, 2026.Tue 06 Oct
- FeatureUsing gcloud CLI, the securitycenter REST API, or client libraries, you can configure Pub/Sub and BigQuery continuous export to receive notifications when findi…Fri 09 Oct
VPC Service Controls — 1
- FeatureVPC Service Controls feature (Status: Preview ) : Support for automated remediation suggestions is available in the VPC Service Controls violation analyzer. Rem…Thu 08 Oct
Virtual Private Cloud — 2
- FeatureGeneral Availability : VPC Flow Logs supports TCP connection logging for VM instances and serverless endpoints. Connection logging captures outbound TCP connect…Wed 07 Oct
- FeatureService producers can let service consumers establish more connections to a Private Service Connect endpoint or backend by configuring the target published serv…Wed 07 Oct
Comments