- Issued:
- 2026-07-09
- Updated:
- 2026-07-09
RHSA-2026:37296 - RHTAS 1.0.1 - GA Release Of the Policy Controller Operator
Synopsis
RHTAS 1.0.1 - GA Release Of the Policy Controller Operator
Type/Severity
Security Advisory Important
Topic
The GA release of the RHTAS Policy Controller Operator. For more details please visit the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
Description
The RHTAS Policy Controller Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20, 4.21, 4.22
Solution
The RHTAS Policy Controller Operator is Helm-based operator for deploying and managing instances of the Sigstore Policy Controller on OpenShift. It is a self-managed on-premise deployment of the Policy Controller Helm Charts available at https://github.com/sigstore/helm-charts/tree/main/charts/policy-controller
Platform Engineers, Software Developers and Security Professionals may use the RHTAS Policy Controller Operator to enforce policies on OCP clusters by using supply-chain metadata.
For details on using the RHTAS Policy Controller Operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Trusted Artifact Signer (RHTAS) | 1.4 | x86_64 |
Fixes
(none)
CVEs
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.