github containerd/stargz-snapshotter v0.19.0

6 hours ago

Security Updates

  • CVE-2026-71482
  • CVE-2026-77395
    • To mitigate this issue, v0.19.0 requires a configuration change to the CRI setting. Specifically, the --image-service-endpoint=unix:///run/containerd-stargz-grpc/containerd-stargz-grpc.sock flag needs to be specified on kubelet. Refer to kubelet configuration section in docs/overview.md for details.

Notable Changes

  • estargz: Fix encoder panic in go 1.27 by emitting footer manually (#2333)
  • ctr-remote i optimize: GPU: migrate to CDI (#2334)
  • fs: add ns query parameter to mirror requests per OCI distribution spec (#2363), thanks to @simonepri
  • fusemanager: Add a dedicated metrics endpoint (#2356), thanks to @mironovgh
  • estargz: add --estargz-parallelism to control build parallelism (#2341), thanks to @simonepri
  • Reset instead of dropping registry traffic in integration tests (#2362), thanks to @kzys
  • Build the k3s node image with make image (#2361), thanks to @kzys
  • simplify waiter implementation in fs (#2270), thanks to @wswsmao
  • estargz: fix panic in GzipDecompressor.ParseFooter on empty Extra field (#2256), thanks to @kylos101
  • go.mod remove excludes that are no longer needed (#2254), thanks to @thaJeztah
  • estargz: deprecate errorutil in favor of native errors.Join (#2247), thanks to @thaJeztah
  • estargz: Build: replace golang.org/x/sync with WaitGroup.Go (go1.25) (#2249), thanks to @thaJeztah
  • modernize some code (#2248), thanks to @thaJeztah

Don't miss a new stargz-snapshotter release

NewReleases is sending notifications on new releases.