Releases: cri-o/cri-o
v1.30.4
CRI-O v1.30.4
The release notes have been generated for the commit range
v1.30.3...v1.30.4 on Fri, 02 Aug 2024 00:18:37 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.30.4.tar.gz
- cri-o.arm64.v1.30.4.tar.gz
- cri-o.ppc64le.v1.30.4.tar.gz
- cri-o.s390x.v1.30.4.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.30.4.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.30.4 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.30.4 \
--signature cri-o.amd64.v1.30.4.tar.gz.sig \
--certificate cri-o.amd64.v1.30.4.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.30.4.tar.gz
> bom validate -e cri-o.amd64.v1.30.4.tar.gz.spdx -d cri-oChangelog since v1.30.3
Changes by Kind
Uncategorized
- Fixed a bug where stopping a container would block all further stop attempts for the same container. (#8392, @sohankunkerkar)
- Reduced "Failed to get pid for pod infra container" NRI message for spoofed containers and lowering the verbosity to
DEBUG. (#8435, @openshift-cherrypick-robot)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.
v1.29.7
CRI-O v1.29.7
The release notes have been generated for the commit range
v1.29.6...v1.29.7 on Fri, 02 Aug 2024 07:22:51 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.29.7.tar.gz
- cri-o.arm64.v1.29.7.tar.gz
- cri-o.ppc64le.v1.29.7.tar.gz
- cri-o.s390x.v1.29.7.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.29.7.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.29.7 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.29.7 \
--signature cri-o.amd64.v1.29.7.tar.gz.sig \
--certificate cri-o.amd64.v1.29.7.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.29.7.tar.gz
> bom validate -e cri-o.amd64.v1.29.7.tar.gz.spdx -d cri-oChangelog since v1.29.6
Changes by Kind
Uncategorized
- Fixed a bug where stopping a container would block all further stop attempts for the same container. (#8393, @sohankunkerkar)
- Reload config should remove pinned images when an empty list is provided (#8325, @sohankunkerkar)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.
v1.28.9
CRI-O v1.28.9
The release notes have been generated for the commit range
v1.28.8...v1.28.9 on Fri, 02 Aug 2024 07:22:55 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.28.9.tar.gz
- cri-o.arm64.v1.28.9.tar.gz
- cri-o.ppc64le.v1.28.9.tar.gz
- cri-o.s390x.v1.28.9.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.28.9.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.28.9 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.28.9 \
--signature cri-o.amd64.v1.28.9.tar.gz.sig \
--certificate cri-o.amd64.v1.28.9.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.28.9.tar.gz
> bom validate -e cri-o.amd64.v1.28.9.tar.gz.spdx -d cri-oChangelog since v1.28.8
Changes by Kind
Uncategorized
- Fixed a bug where stopping a container would block all further stop attempts for the same container. (#8394, @sohankunkerkar)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.
v1.30.3
CRI-O v1.30.3
The release notes have been generated for the commit range
v1.30.2...v1.30.3 on Mon, 01 Jul 2024 11:19:22 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.30.3.tar.gz
- cri-o.arm64.v1.30.3.tar.gz
- cri-o.ppc64le.v1.30.3.tar.gz
- cri-o.s390x.v1.30.3.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.30.3.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.30.3 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.30.3 \
--signature cri-o.amd64.v1.30.3.tar.gz.sig \
--certificate cri-o.amd64.v1.30.3.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.30.3.tar.gz
> bom validate -e cri-o.amd64.v1.30.3.tar.gz.spdx -d cri-oChangelog since v1.30.2
Changes by Kind
Uncategorized
- Reload config should remove pinned images when an empty list is provided (#8323, @sohankunkerkar)
- Remove a container after it fails to start, to prevent copies of it from piling up until it succeeds. (#8297, @openshift-cherrypick-robot)
Dependencies
Added
Nothing has changed.
Changed
- github.com/google/go-containerregistry: v0.18.0 → v0.19.1
Removed
Nothing has changed.
v1.29.6
CRI-O v1.29.6
The release notes have been generated for the commit range
v1.29.5...v1.29.6 on Mon, 01 Jul 2024 11:19:26 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.29.6.tar.gz
- cri-o.arm64.v1.29.6.tar.gz
- cri-o.ppc64le.v1.29.6.tar.gz
- cri-o.s390x.v1.29.6.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.29.6.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.29.6 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.29.6 \
--signature cri-o.amd64.v1.29.6.tar.gz.sig \
--certificate cri-o.amd64.v1.29.6.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.29.6.tar.gz
> bom validate -e cri-o.amd64.v1.29.6.tar.gz.spdx -d cri-oChangelog since v1.29.5
Changes by Kind
Uncategorized
- Remove a container after it fails to start, to prevent copies of it from piling up until it succeeds. (#8299, @openshift-cherrypick-robot)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.
v1.28.8
CRI-O v1.28.8
The release notes have been generated for the commit range
v1.28.7...v1.28.8 on Mon, 01 Jul 2024 11:19:26 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.28.8.tar.gz
- cri-o.arm64.v1.28.8.tar.gz
- cri-o.ppc64le.v1.28.8.tar.gz
- cri-o.s390x.v1.28.8.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.28.8.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.28.8 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.28.8 \
--signature cri-o.amd64.v1.28.8.tar.gz.sig \
--certificate cri-o.amd64.v1.28.8.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.28.8.tar.gz
> bom validate -e cri-o.amd64.v1.28.8.tar.gz.spdx -d cri-oChangelog since v1.28.7
Dependencies
Added
Nothing has changed.
Changed
- github.com/containers/image/v5: 3e133cb → 942a222
Removed
Nothing has changed.
v1.27.8
CRI-O v1.27.8
The release notes have been generated for the commit range
v1.27.7...v1.27.8 on Mon, 01 Jul 2024 11:19:39 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.27.8.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.27.8 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.27.8 \
--signature cri-o.amd64.v1.27.8.tar.gz.sig \
--certificate cri-o.amd64.v1.27.8.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.27.8.tar.gz
> bom validate -e cri-o.amd64.v1.27.8.tar.gz.spdx -d cri-oChangelog since v1.27.7
Dependencies
Added
Nothing has changed.
Changed
- github.com/containers/image/v5: 67ee9a0 → cbfda54
Removed
Nothing has changed.
v1.30.2
CRI-O v1.30.2
The release notes have been generated for the commit range
v1.30.1...v1.30.2 on Mon, 03 Jun 2024 12:47:13 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.30.2.tar.gz
- cri-o.arm64.v1.30.2.tar.gz
- cri-o.ppc64le.v1.30.2.tar.gz
- cri-o.s390x.v1.30.2.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.30.2.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.30.2 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.30.2 \
--signature cri-o.amd64.v1.30.2.tar.gz.sig \
--certificate cri-o.amd64.v1.30.2.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.30.2.tar.gz
> bom validate -e cri-o.amd64.v1.30.2.tar.gz.spdx -d cri-oChangelog since v1.30.1
Changes by Kind
Uncategorized
- Fix CVE-2024-5154 where a malicious container image could make a symlink of
/proc/mountson the host, out of the container's rootfs (#8231, @openshift-cherrypick-robot) - Fix memory leakage when sending a failing port-forward request (#8206, @openshift-cherrypick-robot)
- Fix the bug that cri-o stops watching container exits after it gets an fsnotify error (#8209, @openshift-cherrypick-robot)
Dependencies
Added
Nothing has changed.
Changed
- github.com/containers/image/v5: ea4fcca → f8d6234
Removed
Nothing has changed.
v1.29.5
CRI-O v1.29.5
The release notes have been generated for the commit range
v1.29.4...v1.29.5 on Sun, 02 Jun 2024 00:18:58 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.29.5.tar.gz
- cri-o.arm64.v1.29.5.tar.gz
- cri-o.ppc64le.v1.29.5.tar.gz
- cri-o.s390x.v1.29.5.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.29.5.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.29.5 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.29.5 \
--signature cri-o.amd64.v1.29.5.tar.gz.sig \
--certificate cri-o.amd64.v1.29.5.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.29.5.tar.gz
> bom validate -e cri-o.amd64.v1.29.5.tar.gz.spdx -d cri-oChangelog since v1.29.4
Changes by Kind
Ci
- Build s390x statically linked binaries using musl libc. (#8125, @saschagrunert)
Bug or Regression
- Fix CVE-2024-5154 where a malicious container image could make a symlink of
/proc/mountson the host, out of the container's rootfs(#8232, @ kwilczynski)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.
v1.28.7
CRI-O v1.28.7
The release notes have been generated for the commit range
v1.28.6...v1.28.7 on Mon, 03 Jun 2024 07:21:42 UTC.
Downloads
Download one of our static release bundles via our Google Cloud Bucket:
- cri-o.amd64.v1.28.7.tar.gz
- cri-o.arm64.v1.28.7.tar.gz
- cri-o.ppc64le.v1.28.7.tar.gz
- cri-o.s390x.v1.28.7.tar.gz
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.28.7.tar.gz \
--certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.28.7 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/cri-o \
--certificate-github-workflow-ref refs/tags/v1.28.7 \
--signature cri-o.amd64.v1.28.7.tar.gz.sig \
--certificate cri-o.amd64.v1.28.7.tar.gz.certTo verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.v1.28.7.tar.gz
> bom validate -e cri-o.amd64.v1.28.7.tar.gz.spdx -d cri-oChangelog since v1.28.6
Changes by Kind
Ci
- Build s390x statically linked binaries using musl libc. (#8126, @saschagrunert)
Bug or Regression
- Fix CVE-2024-3154 , a security flaw where CRI-O allowed users to specify annotations that changed specific fields in the runtime. One consequence is a user can change the systemd properties of the container, allowing unsafe properties to be set by the runtime (#8086, @haircommander)
Uncategorized
- Keep track of exec calls for a container, and make sure to kill them when a container is being stopped (#8096, @kwilczynski)
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.