Fixed CVEs:
- CVE-2026-22860: rubygem-rack: Rack Directory Traversal via Rack:Directory
Package Updates:
- Updates director-ruby-3.3 from 3.3.9 to 3.3.10
- Updates nginx from 1.29.3 to 1.29.5
Updates:
- Updates mariadb-connector from 3.4.7 to 3.4.8
- Updates nats-server from 2.11.2 to 2.12.5
- Updates postgresql-13 from 13.22 to 13.23
- Updates postgresql-15 from 15.14 to 15.17
What's Changed
- Log response body if config server returns non-JSON by @jochenehret in #2638
- Remove unnecessary -z flag from tar extraction commands by @mdzhigarov in #2635
- Bump golangci/golangci-lint-action from 8 to 9 by @dependabot[bot] in #2639
- Fix CLI Output for prefix ip addresses by @fmoehler in #2637
- add prefix to network settings for dynamic and vip network by @fmoehler in #2641
- ci: build warden-cpi noble image by @KauzClay in #2643
- CI: residual fixes for Jammy -> Noble by @aramprice in #2645
- Bump actions/checkout from 5 to 6 by @dependabot[bot] in #2644
- CI: stop installing clang on integration image by @aramprice in #2646
- CI: use the source bpm-release for Jammy tests by @aramprice in #2648
- Fix OS detection in DirectorStemcellOwner to read from system files by @s4heid in #2640
- CI: pass setmcell-os to BDRATs specs by @aramprice in #2650
- Spec: remove error class from spec expectation by @aramprice in #2653
- Add metrics for VM states by @yuriadam-sap in #2649
- Noble cut over by @aramprice in #2655
- Replace "magic" strings with constants or StringInquirer by @aramprice in #2659
- Fix failing heartbeat related tests by @yuriadam-sap in #2660
- Fix undefined method
detached?for String by @neddp in #2662 - Add a new option to allow vm recreation filter based on vm age by @Alphasite in #2656
- Fix regex operator typo in health monitor spec by @neddp in #2666
- CI: fix deprecated property by @aramprice in #2667
- Add scheduled metrics cleanup job by @neddp in #2654
- CI: update start-bosh for cgroupsv2 by @aramprice in #2668
- CI: update docker-cpi for cgroups v2 by @aramprice in #2669
- CI: set default-cgroupns-mode mode in daemon.json by @aramprice in #2670
- Ci docker cpi fixes by @aramprice in #2671
- Ci docker cpi fixes by @aramprice in #2672
- CI: increase spec timeouts by @aramprice in #2674
- docker-cpi: fix for container dns on noble by @aramprice in #2673
- CI: order expected results from db to prevent flakes by @aramprice in #2675
- CI: explicitly set DNS for the docker daemon by @aramprice in #2677
- Add nic_group handling for VIP networks by @neddp in #2658
- Fix missing instance metrics_dir method by @neddp in #2679
- Use local stemcell file by @mariash in #2680
- Fix unit spec flakes by @aramprice in #2681
- Fix stemcell os by @mariash in #2682
- bump CI timouts for upgrade tests by @mkocher in #2684
- Ci fix brats by @aramprice in #2683
- CI: Rename bats-fips to fips-bats by @mariash in #2686
New Contributors
- @jochenehret made their first contribution in #2638
- @mdzhigarov made their first contribution in #2635
- @KauzClay made their first contribution in #2643
- @yuriadam-sap made their first contribution in #2649
- @neddp made their first contribution in #2662
- @Alphasite made their first contribution in #2656
Full Changelog: v282.1.2...v282.1.3