Official Packages
See attached binaries.
Changelog
Added
- Port runc security patches for CVEs 2025-3133, 2025-52881, and 2025-52565.
- Support volatile overlayfs remounting.
- Add
featurescommand to sysbox-runc. - Enable newer versions of runc to run inside Sysbox containers properly by trapping openat2 system call to allow access to sysbox-fs mounts under /proc and /sys.
- sysbox-deploy-k8s: add support for k8s v1.33, v1.34, and v1.35. Deprecate support for v1.29 to v1.31.
- sysbox-deploy-k8s: enable compatibility with K8s user-namespaces (requires containerd v2.0.5+ or CRI-O).
- sysbox-deploy-k8s: don't install CRI-O when K8s cluster has containerd 2.0.5+.
- Update docs to indicate support for K8s user-namespaces (requires
hostUsers: falsedirective in pod spec).
Checksums
sha256sum sysbox-ce_0.7.0.linux_amd64.deb
eeff273671467b8fa351ab3d40709759462dc03d9f7b50a1b207b37982ce40a9 sysbox-ce_0.7.0.linux_amd64.deb
$ sha256sum sysbox-ce_0.7.0.linux_arm64.deb
eae9c0e91ddd39bd1826d6a7a313a73d42a8449ef5113e9d6d118b559cb809ba sysbox-ce_0.7.0.linux_arm64.deb