containerd
Industry-standard container runtime
containerd 2.4.0 defaults user namespace networking to on and purges two years of deprecated config.
◆Recent moves
- 3d ago
containerd 2.4.0: user namespace networking defaults on, deprecated configs removed
⚡ SPARKcontainerd 2.4.0 ships with UserNamespacesHostNetwork defaulting to true and /proc/interrupts masked in containers by default — two security default changes that affect how containers interact with the host. EROFS gains a warm image cache and Prometheus layer content metrics. The release removes CDI, OTLP tracing, and old CNI bin_dir configuration, clearing the accumulated deprecated surface from the 2.3 LTS cycle.
View source ↗ - 3d ago
containerd API 1.12.0
The 1.12.0 API release aligns with containerd 2.4.0 and adds the UpdateSandbox RPC, enabling sandbox controller updates to propagate to the shim. Shim mount capabilities are formalized as a first-class API extension, deprecating the older runtime-allow-mounts annotation. These additions enable more dynamic sandbox lifecycle operations than the current static configuration model.
View source ↗ - 5d ago
containerd 2.4.0-rc.0
Release candidate for containerd 2.4.0 with the same feature set as the GA. No distinct user-facing content beyond what shipped in the final 2.4.0 release.
View source ↗ - 5d ago
containerd API 1.12.0-rc.1
API release candidate for the 1.12.0 series aligned with the 2.4.0 release cycle. Content matches the 1.12.0 GA; no distinct user-facing changes.
View source ↗ - 15d ago
containerd 1.7.35: CVE-2026-53495 security patch for the 1.7 LTS branch
Security patch for the 1.7.x LTS branch fixing CVE-2026-53495 by stripping sensitive authentication headers when following registry descriptor URL redirects. Windows log scrubbing defaults to enabled. Part of the coordinated multi-branch security patch cycle that simultaneously addressed the same CVE across 1.7, 2.0, 2.2, and 2.3.
View source ↗ - 15d ago
containerd 2.0.12: CVE-2026-53495 patched in the 2.0 branch
Security patch for 2.0.x covering CVE-2026-53495 (auth header stripping on descriptor URL redirects), plus OCI 403 error body surfacing and a Windows SystemTemp fix. Part of the same coordinated security patch cycle across multiple release branches.
View source ↗