github cri-o/cri-o v1.28.7

latest release: v1.30.2
23 days ago
  • CRI-O v1.28.7
    • Downloads
    • Changelog since v1.28.6
      • Changes by Kind
        • Ci
        • Bug or Regression
        • Uncategorized
    • Dependencies
      • Added
      • Changed
      • Removed

CRI-O v1.28.7

The release notes have been generated for the commit range
v1.28.6...v1.28.7 on Mon, 03 Jun 2024 07:21:42 UTC.

Downloads

Download one of our static release bundles via our Google Cloud Bucket:

To verify the artifact signatures via cosign, run:

> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.v1.28.7.tar.gz \
    --certificate-identity https://github.com/cri-o/cri-o/.github/workflows/test.yml@refs/tags/v1.28.7 \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com \
    --certificate-github-workflow-repository cri-o/cri-o \
    --certificate-github-workflow-ref refs/tags/v1.28.7 \
    --signature cri-o.amd64.v1.28.7.tar.gz.sig \
    --certificate cri-o.amd64.v1.28.7.tar.gz.cert

To verify the bill of materials (SBOM) in SPDX format using the bom tool, run:

> tar xfz cri-o.amd64.v1.28.7.tar.gz
> bom validate -e cri-o.amd64.v1.28.7.tar.gz.spdx -d cri-o

Changelog since v1.28.6

Changes by Kind

Ci

Bug or Regression

  • Fix CVE-2024-3154 , a security flaw where CRI-O allowed users to specify annotations that changed specific fields in the runtime. One consequence is a user can change the systemd properties of the container, allowing unsafe properties to be set by the runtime (#8086, @haircommander)

Uncategorized

  • Keep track of exec calls for a container, and make sure to kill them when a container is being stopped (#8096, @kwilczynski)

Dependencies

Added

Nothing has changed.

Changed

Nothing has changed.

Removed

Nothing has changed.

Don't miss a new cri-o release

NewReleases is sending notifications on new releases.