Changes since Alpha 3535.0.0
Security fixes:
- Go (CVE-2023-24532)
- GnuTLS (CVE-2023-0361)
- curl (CVE-2023-23914, CVE-2023-23915, CVE-2023-23916)
- git (CVE-2023-22490, CVE-2023-23946)
- pkgconf (CVE-2023-24056)
- python (CVE-2023-24329)
- vim (CVE-2023-0288, CVE-2023-0433)
Bug fixes:
- Restored the support to specify OEM partition files in Ignition when
/usr/share/oem
is given as initrd mount point (bootengine#58)
Changes:
- Added
pigz
to the image, a parallel gzip implementation, which is useful to speed up the (de)compression for large container image imports/exports (coreos-overlay#2504) - Added new image signing pub key to
flatcar-install
, needed for download verification of releases built from July 2023 onwards, if you have copies offlatcar-install
or the image signing pub key, you need to update them as well (init#92) - Enabled elfutils support in systemd-coredump. A backtrace will now appear in the journal for any program that dumps core (coreos-overlay#2489)
- Specifying the OEM filesystem in Ignition to write files to
/usr/share/oem
is not needed anymore (bootengine#58)
Updates:
- Go (1.19.7)
- Linux (5.15.103 (includes 5.15.102, 5.15.101, 5.15.100, 5.15.99))
- Linux Firmware (20230310)
- Rust (1.68.0)
- ca-certificates (3.89)
- open-vm-tools (12.2.0)
- GLib (2.74.5)
- GnuTLS (3.8.0)
- SDK: portage (3.0.44)
- SDK: python (3.10.10)
- bind tools (9.16.37)
- curl (7.88.1 (includes 7.88.0))
- diffutils (3.9)
- gcc (12.2.1)
- git (2.39.2)
- libpcap (1.10.3 (includes 1.10.2))
- qemu guest agent (7.1.0)
- socat (1.7.4.4)
- traceroute (2.1.1)
- vim (9.0.1363)