containerd

Developer Tools

The industry-standard container runtime underneath Docker and Kubernetes.

Latest v2.3.3 · by CNCFWebsitecontainerd/containerd

Release activity

Release activity — 11 releases across 5 days since Jun 18, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 18, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
MondayNo releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 20261 release on Aug 10, 2026
TuesdayNo releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 20261 release on Aug 5, 2026
Thursday5 releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 20263 releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 20261 release on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026

11 releases since Jun 18, 2026, busiest day 5

Changelog

v2.4.0-beta.0Pre-release

containerd 2.4.0-beta.0

Added 6
  • Include media type in content create event
  • Support warm image cache for erofs snapshotter
  • Add parent path to runc checkpoint options
  • Introspect OCI runtime features for non-runc runtimes
  • Add forward References to the GC collection context
  • Add max size label for snapshots
Changed 1
  • Use klauspost/compress/gzip for decode
Fixed 1
  • Fix sandbox task API endpoints for non-runc runtimes
Removed 1
  • Remove restore in CreateContainer

Welcome to the v2.4.0-beta.0 release of containerd! This is a pre-release of containerd

containerd 2.4 is a regular (non-LTS) release with a shorter support window, intended for users who want to adopt new features sooner. As the release following the 2.3 LTS, it is the point in the release cycle where previously deprecated features may be removed, so this release may include breaking changes; check the notes below and clear any deprecation warnings from your current version before upgrading.

Users prioritizing stability and a longer support lifecycle should stay on the 2.3 LTS release.

This is a beta release and some functionality is still under development.

Highlights
  • Include media type in content create event (#13833)
  • Support warm image cache for erofs snapshotter (#13813)
  • Add parent path to runc checkpoint options (#13699)
Container Runtime Interface (CRI)
  • Introspect OCI runtime features for non-runc runtimes (#13504)
Image Distribution
  • Use klauspost/compress/gzip for decode (#13560)
Image Storage
  • Add forward References to the GC collection context (#13634)
Snapshotters
  • Add max size label for snapshots (#13520)
Breaking
  • Remove restore in CreateContainer (#13871)
Deprecations
  • Fix sandbox task API endpoints for non-runc runtimes (#13360)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Maksym Pavlenko
  • Samuel Karp
  • Akihiro Suda
  • Derek McGowan
  • Wei Fu
  • Sebastiaan van Stijn
  • Chris Henzie
  • Paweł Gronowski
  • Mike Brown
  • Brian Goff
  • Jordan Liggitt
  • Austin Vazquez
  • Kazuyoshi Kato
  • Kir Kolyshkin
  • Phil Estes
  • Sergey Kanzhelev
  • ningmingxiao
  • Ahmet Alp Balkan
  • Akhil Mohan
  • Chris Ayoub
  • Damien Grisonnet
  • Esteban Ginez
  • Laura Lorenz
  • Maksim An
  • Abhishek Bhunia
  • Alan Grosskurth
  • Albin Kerouanton
  • Alex Lyn
  • Aman Raj
  • Amir Alavi
  • Amit Barve
  • Andrew Halaney
  • AprilNEA
  • Arjun Yogidas
  • Ayato Tokubi
  • Aysha Afrah Ziya
  • Ben Cressey
  • Bing Hongtao
  • Chris Crone
  • Craig Gumbley
  • Daniel De Graaf
  • Davanum Srinivas
  • Dr. Jan-Philip Gehrcke
  • Gao Xiang
  • Harshal Patel
  • Henry Wang
  • Kohei Tokunaga
  • Krisztian Litkey
  • LEI WANG
  • Mikhail Dmitrichenko
  • Nikolaus Schuetz
  • Paco Xu
  • Philip Laine
  • SaloniRathi
  • Tianon Gravi
  • ayush-panta
  • crawfordxx
  • cshung
  • s3onghyun
  • 归寂
  • 徐晓伟
Dependency Changes
  • cyphar.com/go-pathrs v0.2.1 -> v0.2.4
  • github.com/Microsoft/hcsshim v0.15.0-rc.1 -> v0.15.0-rc.3
  • github.com/ProtonMail/go-crypto v1.4.1 new
  • github.com/cilium/ebpf v0.16.0 -> v0.17.3
  • github.com/cloudflare/circl v1.6.3 new
  • github.com/containerd/containerd/api v1.11.0 -> v1.12.0-beta.0
  • github.com/containerd/imgcrypt/v2 v2.0.2 -> v2.0.3
  • github.com/containerd/nri v0.12.0 -> v0.12.1
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/containerd/typeurl/v2 v2.2.3 -> v2.3.0
  • github.com/containers/ocicrypt v1.2.1 -> v1.3.2
  • github.com/cyphar/filepath-securejoin v0.6.0 -> v0.6.1
  • github.com/erofs/go-erofs v0.3.0 -> v0.3.1
  • github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
  • github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
  • github.com/intel/goresctrl v0.12.0 -> v0.13.0
  • github.com/klauspost/compress v1.18.5 -> v1.19.1
  • github.com/mdlayher/socket v0.5.1 -> v0.6.0
  • github.com/mdlayher/vsock v1.2.1 -> v1.3.0
  • github.com/miekg/pkcs11 v1.1.1 -> v1.1.2
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/opencontainers/selinux v1.13.1 -> v1.15.1
  • github.com/pelletier/go-toml/v2 v2.3.0 -> v2.4.3
  • github.com/prometheus/client_golang v1.23.2 -> v1.24.0
  • github.com/prometheus/common v0.67.5 -> v0.70.0
  • github.com/prometheus/procfs v0.19.2 -> v0.21.1
  • github.com/smallstep/pkcs7 v0.1.1 -> v0.2.1
  • go.etcd.io/bbolt v1.4.3 -> v1.5.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0 -> v0.69.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 -> v0.69.0
  • go.opentelemetry.io/otel v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
  • go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
  • go.yaml.in/yaml/v3 v3.0.4 new
  • golang.org/x/crypto v0.49.0 -> v0.53.0
  • golang.org/x/mod v0.35.0 -> v0.38.0
  • golang.org/x/net v0.52.0 -> v0.56.0
  • golang.org/x/oauth2 v0.35.0 -> v0.36.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.43.0 -> v0.47.0
  • golang.org/x/term v0.41.0 -> v0.44.0
  • golang.org/x/text v0.35.0 -> v0.38.0
  • google.golang.org/genproto/googleapis/api 9d38bb4040a9 -> 3dc84a4a5aaa
  • google.golang.org/genproto/googleapis/rpc 6f92a3bedf2d -> 3dc84a4a5aaa
  • google.golang.org/grpc v1.80.0 -> v1.82.1
  • k8s.io/api v0.36.0 -> v0.36.3
  • k8s.io/apimachinery v0.36.0 -> v0.36.3
  • k8s.io/client-go v0.36.0 -> v0.36.3
  • k8s.io/component-base v0.36.0 -> v0.36.3
  • k8s.io/cri-api v0.36.0 -> v0.36.3
  • k8s.io/cri-client v0.36.0 -> v0.36.3
  • k8s.io/cri-streaming v0.36.0 -> v0.36.3
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.3.3
  • tags.cncf.io/container-device-interface v1.1.0 -> 49ac08dcf160

Previous release can be found at v2.3.0

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.4.0-beta.0 went
api/v1.12.0-beta.0Pre-release

containerd API 1.12.0-beta.0

Added 2
  • Include media type in content create event
  • Add parent path to runc checkpoint options
Deprecated 1
  • Fix sandbox task API endpoints for non-runc runtimes

Welcome to the api/v1.12.0-beta.0 release of containerd! This is a pre-release of containerd

The 13th release for the containerd 1.x API aligns with the containerd 2.4 release.

Highlights
  • Include media type in content create event (#13833)
  • Add parent path to runc checkpoint options (#13699)
Deprecations
  • Fix sandbox task API endpoints for non-runc runtimes (#13360)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Maksym Pavlenko
  • Derek McGowan
  • Jordan Liggitt
  • Samuel Karp
  • Wei Fu
  • Kohei Tokunaga
  • Philip Laine
  • Sergey Kanzhelev
Changes
  • Prepare release notes for api/v1.12.0-beta.0 (#13899)
    • 0ff04dc3f Prepare release notes for api/v1.12.0-beta.0
  • Include media type in content create event (#13833)
    • a452c2e23 Include media type in content create event
  • build(deps): bump golang.org/x/net from 0.51.0 to 0.55.0 in /api (#13819)
    • 52c5f1f64 build(deps): bump golang.org/x/net from 0.51.0 to 0.55.0 in /api
  • build(deps): bump github.com/containerd/ttrpc to v1.2.9 (#13740)
    • 658a1c78b build(deps): bump github.com/containerd/ttrpc to v1.2.9
  • Add parent path to runc checkpoint options (#13699)
    • ea0ed51e2 shim: allow specifying runc's --parent-path during checkpointing
  • Update typeurl/v2 to v2.3.0 to drop gogo dependency (#13490)
    • ce3914324 Update typeurl/v2 to v2.3.0 to drop gogo dependency
  • do not hide linitng errors (#13423)
  • Fix sandbox task API endpoints for non-runc runtimes (#13360)
    • ac01ae5c2 protos: include task API address to CreateTaskRequest
Dependency Changes
  • github.com/containerd/ttrpc v1.2.5 -> v1.2.9
  • github.com/containerd/typeurl/v2 v2.1.1 -> v2.3.0
  • golang.org/x/net v0.48.0 -> v0.55.0
  • golang.org/x/sys v0.39.0 -> v0.46.0
  • golang.org/x/text v0.32.0 -> v0.37.0
  • google.golang.org/genproto/googleapis/rpc ff82c1b0f217 -> a57be14db171
  • google.golang.org/grpc v1.79.3 -> v1.81.1
  • google.golang.org/protobuf v1.36.10 -> v1.36.11

Previous release can be found at api/v1.11.0

View originalPermalink
How api/v1.12.0-beta.0 went
v2.3.3

containerd 2.3.3

Fixed 6
  • Set SystemTemp environment variable on Windows so temp directory overrides work for SYSTEM services
  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit
  • Reject CreateContainer calls when the target sandbox is not running
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks
  • Surface OCI error bodies in registry 403 responses by falling back to GET requests
  • Align default 4K mkfs block size for EROFS across all platforms

Welcome to the v2.3.3 release of containerd!

The third patch release for containerd 2.3 contains various fixes and updates.

Highlights
  • Set SystemTemp environment variable on Windows so temp directory overrides work for SYSTEM services (#13694)
Container Runtime Interface (CRI)
  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit (#13697)
  • Reject CreateContainer calls when the target sandbox is not running (#13668)
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks (#13645)
Image Distribution
  • Surface OCI error bodies in registry 403 responses by falling back to GET requests (#13738)
Snapshotters
  • Align default 4K mkfs block size for EROFS across all platforms (#13632)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Maksym Pavlenko
  • Samuel Karp
  • Chris Henzie
  • Phil Estes
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Austin Vazquez
  • Chris Crone
  • Derek McGowan
  • Maksim An
  • crawfordxx
  • cshung
  • lauralorenz
Changes
  • Prepare release notes for v2.3.3 (#13750)
  • CI: migrate Vagrant to Lima (#13744)
  • remotes: surface OCI error body in registry 4xx responses (#13738)
    • 457fba3a3 remotes: surface OCI error body on HEAD 403 via GET fallback
  • Update go to 1.26.5 (#13732)
  • ci: pin fog-json to resolve gem conflict (#13711)
    • 5be0495df ci: pin fog-json to resolve gem conflict
  • Fix nil pointer dereference in NRI GetIPs (#13697)
    • 36c713971 Fix nil pointer dereference in NRI GetIPs
  • Set SystemTemp env var to config temp on Windows (#13694)
    • 26dce170d Set SystemTemp env var to config temp on Windows
  • update runhcs to v0.15.0-rc.3 (#13693)
  • Update to current setup-go version (#13686)
    • 3e97edeb7 Update to current setup-go version
  • cri: reject CreateContainer when sandbox is not running (#13668)
    • 8856b0f9c cri: reject CreateContainer when sandbox is not running
  • update runhcs to v0.15.0-rc.2 (#13666)
  • test: fix flaky image timestamp check on coarse clocks (#13643)
    • 168d56783 test: fix flaky image timestamp check on coarse clocks
  • Add defer in event of mid-function failures in RunPodSandbox to avoid mount leaks (#13645)
    • d1db61db8 Add deferred call to ShutdownSandbox to avoid leaks
  • erofs: align default mkfs block size across platforms (#13632)
    • 01b0f03f6 erofs: align default mkfs block size across platforms
Dependency Changes

This release has no dependency changes

Previous release can be found at v2.3.2

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.3.3 went
v2.2.6

containerd 2.2.6

Fixed 4
  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit
  • Reject CreateContainer calls when the target sandbox is not running
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks
  • Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution

Welcome to the v2.2.6 release of containerd!

The sixth patch release for containerd 2.2 contains various fixes and updates.

Highlights
Container Runtime Interface (CRI)
  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit (#13696)
  • Reject CreateContainer calls when the target sandbox is not running (#13669)
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks (#13644)
Image Distribution
  • Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution (#13620)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Phil Estes
  • Akihiro Suda
  • Joseph Zhang
  • Maksym Pavlenko
  • crawfordxx
  • lauralorenz
Changes
  • Prepare release notes for v2.2.6 (#13751)
  • CI: migrate Vagrant to Lima (#13745)
  • Update go to 1.26.5/1.25.12 (#13726)
  • ci: pin fog-json to resolve gem conflict (#13714)
    • 8f123e4f7 ci: pin fog-json to resolve gem conflict
  • Fix nil pointer dereference in NRI GetIPs (#13696)
    • d3e1a2be9 Fix nil pointer dereference in NRI GetIPs
  • cri: reject CreateContainer when sandbox is not running (#13669)
    • 872a9502e cri: reject CreateContainer when sandbox is not running
  • Add defer in event of mid-function failures in RunPodSandbox to avoid mount leaks (#13644)
    • ba7605ee7 Add deferred call to ShutdownSandbox to avoid leaks
  • fix: avoid content storage pollution by limiting the fallback on ref resolution (#13620)
    • 36c4275ee fix:avoid content storage pollution by limiting the fallback on ref resolution
Dependency Changes

This release has no dependency changes

Previous release can be found at v2.2.5

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.2.6 went
v2.0.11

containerd 2.0.11

Fixed 1
  • Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution

Welcome to the v2.0.11 release of containerd!

The eleventh patch release for containerd 2.0 contains various fixes and updates.

Highlights
Image Distribution
  • Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution (#13622)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Joseph Zhang
  • Phil Estes
Changes
  • Prepare release notes for v2.0.11 (#13752)
    • 24a2ac9db Prepare release notes for v2.0.11
  • Update go to 1.26.5/1.25.12 (#13730)
  • ci: pin fog-json to resolve gem conflict (#13713)
    • f89266ecb ci: pin fog-json to resolve gem conflict
  • fix: avoid content storage pollution by limiting the fallback on ref resolution (#13622)
    • 179b642d6 fix:avoid content storage pollution by limiting the fallback on ref resolution
Dependency Changes

This release has no dependency changes

Previous release can be found at v2.0.10

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.31 (Ubuntu 20.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on non-glibc Linux distributions. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.0.11 went
v1.7.34

containerd 1.7.34

Fixed 1
  • Fix lost container exit events when events arrive before container info is cached

Welcome to the v1.7.34 release of containerd!

The thirty-fourth patch release for containerd 1.7 contains various fixes and updates.

Highlights
Container Runtime Interface (CRI)
  • Fix lost container exit events when events arrive before container info is cached (#11634)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Chris Henzie
  • Samuel Karp
  • Akihiro Suda
  • Maksym Pavlenko
  • Phil Estes
  • Sopho Merkviladze
  • ningmingxiao
Changes
  • Prepare release notes for v1.7.34 (#13753)
    • 7db112471 Prepare release notes for v1.7.34
  • Update go to 1.26.5/1.25.12 (#13731)
  • ci: pin fog-json to resolve gem conflict (#13712)
    • b84460e50 ci: pin fog-json to resolve gem conflict
  • cri:fix lost container exit events if they arrive before info is cached (#11634)
    • 2fe076ea7 cri:fix lost container exit events if they arrive before info is cached
  • build(deps): bump golang.org/x/* dependencies (#13502)
Dependency Changes
  • golang.org/x/crypto v0.45.0 -> v0.52.0
  • golang.org/x/mod v0.29.0 -> v0.35.0
  • golang.org/x/net v0.47.0 -> v0.55.0
  • golang.org/x/sync v0.18.0 -> v0.20.0
  • golang.org/x/sys v0.38.0 -> v0.45.0
  • golang.org/x/term v0.37.0 -> v0.43.0
  • golang.org/x/text v0.31.0 -> v0.37.0

Previous release can be found at v1.7.33

View originalPermalink
How v1.7.34 went
v2.1.9

containerd 2.1.9

Changed 2
  • Update runc binary to v1.3.6
  • Update Go to 1.26.4/1.25.11
Fixed 5
  • Filter CDI annotations on checkpoint restore in cri
  • Do not re-tag restored checkpoints in cri
  • Make checkpoint restore robust to unexpected archive content in cri
  • Bound user-database file reads in openBoundedUserFile
  • Do not propagate reserved labels from image configs
Security 5
  • Fix CVE-2026-50195
  • Fix CVE-2026-53488
  • Fix CVE-2026-53492
  • Fix CVE-2026-53489
  • Fix CVE-2026-47262

Welcome to the v2.1.9 release of containerd!

The ninth patch release for containerd 2.1 contains various fixes and updates including security patches.

Security Updates

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Chris Henzie
  • Samuel Karp
  • Akihiro Suda
  • Wei Fu
  • Akhil Mohan
  • Ben Cressey
  • Brian Goff
  • Davanum Srinivas
  • Derek McGowan
  • Jared Ledvina
Changes
  • Prepare release notes for v2.1.9 (#13629)
    • b8b3a86e9 Prepare release notes for v2.1.9
    • ee965da63 Merge commit from fork
    • b5e0c4733 Merge commit from fork
    • 02045fd46 cri: filter CDI annotations on checkpoint restore
    • e9c26cf3c Merge commit from fork
    • 2e4583a9f cri: do not re-tag restored checkpoints
    • 6e4ec908a Merge commit from fork
    • 570e69884 cri: make checkpoint restore robust to unexpected archive content
    • 3788b4b9e Merge commit from fork
    • 290420fa7 Bound user-database file reads in openBoundedUserFile
    • bc5014f45 Merge commit from fork
    • 429bcb924 Do not propagate reserved labels from image configs
  • update runc binary to v1.3.6 (#13616)
  • update go to 1.26.4/1.25.11 (#13578)
  • Configure udevd children-max for root-test (#13566)
    • 22515b56f Configure udevd children-max for root-test
  • Clean up disk space in node e2e workflow (#13554)
    • af88d4f60 Clean up disk space in node e2e workflow
  • [github-action] release - Empty allowedSignersFile (#13517)
    • 06df49576 release - Empty allowedSignersFile
Dependency Changes

This release has no dependency changes

Previous release can be found at v2.1.8

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.1.9 went
v1.7.33

containerd 1.7.33

Changed 2
  • Update runc binary to v1.3.6
  • Update Go to 1.26.4 and 1.25.11
Fixed 2
  • Bound user-database file reads in openBoundedUserFile
  • Do not propagate reserved labels from image configs
Security 3
  • Address CVE-2026-53488 in containerd
  • Address CVE-2026-47262 in containerd
  • Address CVE-2026-34986 in go-jose by bumping go-jose/go-jose/v3 to v3.0.5

Welcome to the v1.7.33 release of containerd!

The thirty-third patch release for containerd 1.7 contains various fixes and updates including security patches.

Security Updates

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akihiro Suda
  • Akhil Mohan
  • Ben Cressey
  • Davanum Srinivas
  • Sopho Merkviladze
Changes
  • Prepare release notes for v1.7.33 (#13631)
    • 7517e6737 Prepare release notes for v1.7.33
    • ab306518a Merge commit from fork
    • d34cdafda Merge commit from fork
    • 9ab2b7a89 Bound user-database file reads in openBoundedUserFile
    • 1e9806f90 Merge commit from fork
    • 4d8ba4d23 Do not propagate reserved labels from image configs
  • update runc binary to v1.3.6 (#13615)
  • update go to 1.26.4/1.25.11 (#13579)
  • Configure udevd children-max for root-test (#13564)
    • e884e964e Configure udevd children-max for root-test
  • Clean up disk space in node e2e workflow (#13552)
    • b9e756888 Clean up disk space in node e2e workflow
  • Bump go-jose/go-jose/v3 to v3.0.5 to fix GHSA-78h2-9frx-2jm8 (#13467)
    • 4dfc1844e Bump go-jose to v3.0.5 to address CVE-2026-34986
Dependency Changes
  • github.com/go-jose/go-jose/v3 v3.0.4 -> v3.0.5

Previous release can be found at v1.7.32

View originalPermalink
How v1.7.33 went
v2.0.10

containerd 2.0.10

Changed 2
  • Update runc binary to v1.3.6
  • Update Go to 1.26.4 and 1.25.11
Fixed 2
  • Bound user-database file reads in openBoundedUserFile
  • Do not propagate reserved labels from image configs
Security 2
  • Fix CVE-2026-53488
  • Fix CVE-2026-47262

Welcome to the v2.0.10 release of containerd!

The tenth patch release for containerd 2.0 includes various bug fixes and updates including security patches.

Security Updates

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akhil Mohan
  • Akihiro Suda
  • Ben Cressey
  • Davanum Srinivas
  • Paweł Gronowski
  • Sebastiaan van Stijn
Changes
  • Prepare release notes for v2.0.10 (#13630)
    • cbbd21672 Prepare release notes for v2.0.10
    • 200a4005f Merge commit from fork
    • da4098647 Merge commit from fork
    • 03a19324f Bound user-database file reads in openBoundedUserFile
    • 126177ea4 Merge commit from fork
    • bbf4a2b8e Do not propagate reserved labels from image configs
  • update runc binary to v1.3.6 (#13619)
    • a15e98122 update runc binary to v1.3.6
    • ba2ed2a5e [release/2.2] update runc binary to v1.3.5
    • 474184497 runc: Update runc binary to v1.3.4
  • update go to 1.26.4/1.25.11 (#13581)
  • Configure udevd children-max for root-test (#13565)
    • 55bdc8bc5 Configure udevd children-max for root-test
  • Clean up disk space in node e2e workflow (#13553)
    • 6d81e8867 Clean up disk space in node e2e workflow
Dependency Changes

This release has no dependency changes

Previous release can be found at v2.0.9

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.31 (Ubuntu 20.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on non-glibc Linux distributions. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.0.10 went
v2.3.2

containerd 2.3.2

Changed 7
  • Allow the last host to retry on transient network errors
  • Update golang.org/x/crypto to v0.53.0
  • Update golang.org/x/mod to v0.36.0
  • Update golang.org/x/net to v0.55.0
  • Update golang.org/x/sync to v0.21.0
  • Update golang.org/x/sys to v0.46.0
  • Update golang.org/x/term to v0.44.0
Fixed 7
  • Fix data race when reading shim logs on Windows
  • Fix container startup failures caused by concurrent task RPC timeouts during slow container creation
  • Filter CDI annotations on checkpoint restore
  • Do not re-tag restored checkpoints
  • Make checkpoint restore robust to unexpected archive content
  • Bound user-database file reads in openUserFile
  • Do not propagate reserved labels from image configs
Security 5
  • Fix CVE-2026-50195
  • Fix CVE-2026-53488
  • Fix CVE-2026-53492
  • Fix CVE-2026-53489
  • Fix CVE-2026-47262

Welcome to the v2.3.2 release of containerd!

The second patch release for containerd 2.3 contains various fixes and updates including security patches.

Security Updates
Highlights
  • Fix a data race when reading shim logs on Windows (#13522)
Image Distribution
  • Allow the last host to retry on transient network errors (#13591)
Runtime
  • Fix container startup failures caused by concurrent task RPC timeouts during slow container creation (#13512)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akihiro Suda
  • Derek McGowan
  • Akhil Mohan
  • Austin Vazquez
  • Ben Cressey
  • Brian Goff
  • Maksym Pavlenko
  • Sebastiaan van Stijn
  • Sergey Kanzhelev
Changes
  • Prepare release notes for v2.3.2 (#13627)
    • fb8ca00b0 Prepare release notes for v2.3.2
    • 9c69960ba Merge commit from fork
    • 0f6251520 Merge commit from fork
    • 91d7471e2 cri: filter CDI annotations on checkpoint restore
    • 7c2e086bf Merge commit from fork
    • dae67765f cri: do not re-tag restored checkpoints
    • 94aa1e2c1 Merge commit from fork
    • 09599078f cri: make checkpoint restore robust to unexpected archive content
    • e1fdb8d22 Merge commit from fork
    • ff1d116ef Bound user-database file reads in openUserFile
    • d156e07cb Merge commit from fork
    • f99aad54a Do not propagate reserved labels from image configs
  • vendor: golang.org/x/crypto v0.53.0 (#13608)
    • 0b9469501 [release/2.3] vendor: golang.org/x/crypto v0.53.0
  • resolver: retry on transient network errors (#13591)
    • 983bbddc1 resolver: retry on transient network errors
  • update runc binary to v1.4.3 (#13601)
  • update go to 1.26.4 (#13580)
    • 8a49dfe85 update go to 1.26.4
    • 5aa6bb2b7 remove 1.26.2 from CI builds as it is not supported any longer due to the dependency
  • Configure udevd children-max for root-test (#13568)
    • bfb8aebc0 Configure udevd children-max for root-test
  • core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read (#13522)
    • 62ceafff0 core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read
  • runc-shim: don't hold the service lock across runc create (#13512)
    • 9b0c0dc58 runc-shim: don't hold the service lock across runc create
  • contrib/checkpoint: increase timeouts to 30s (#13459)
    • f588bc6fb contrib/checkpoint: increase timeouts to 30s
Dependency Changes
  • golang.org/x/crypto v0.49.0 -> v0.53.0
  • golang.org/x/mod v0.35.0 -> v0.36.0
  • golang.org/x/net v0.52.0 -> v0.55.0
  • golang.org/x/sync v0.20.0 -> v0.21.0
  • golang.org/x/sys v0.43.0 -> v0.46.0
  • golang.org/x/term v0.41.0 -> v0.44.0
  • golang.org/x/text v0.35.0 -> v0.38.0

Previous release can be found at v2.3.1

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.3.2 went
v2.2.5

containerd 2.2.5

Changed 9
  • Update golang.org/x/crypto to v0.53.0
  • Update golang.org/x/mod to v0.36.0
  • Update golang.org/x/net to v0.55.0
  • Update golang.org/x/sync to v0.21.0
  • Update golang.org/x/sys to v0.46.0
  • Update golang.org/x/term to v0.44.0
Fixed 5
  • Filter CDI annotations on checkpoint restore
  • Do not re-tag restored checkpoints
  • Make checkpoint restore robust to unexpected archive content
  • Bound user-database file reads in openUserFile
  • Do not propagate reserved labels from image configs
Security 5
  • Fix CVE-2026-50195
  • Fix CVE-2026-53488
  • Fix CVE-2026-53492
  • Fix CVE-2026-53489
  • Fix CVE-2026-47262

Welcome to the v2.2.5 release of containerd!

The fifth patch release for containerd 2.2 contains various fixes and updates including security patches.

Security Updates

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akihiro Suda
  • Derek McGowan
  • Maksym Pavlenko
  • Akhil Mohan
  • Ben Cressey
  • Brian Goff
  • Davanum Srinivas
  • Sebastiaan van Stijn
Changes
  • Prepare release notes for v2.2.5 (#13628)
    • 269031099 Prepare release notes for v2.2.5
    • ad59aa564 Merge commit from fork
    • 0b4d23690 Merge commit from fork
    • be8460656 cri: filter CDI annotations on checkpoint restore
    • 347240f72 Merge commit from fork
    • cff578841 cri: do not re-tag restored checkpoints
    • 668cf2c2f Merge commit from fork
    • 357652293 cri: make checkpoint restore robust to unexpected archive content
    • d43da05af Merge commit from fork
    • 30708e8d1 Bound user-database file reads in openUserFile
    • 028647ea2 Merge commit from fork
    • b6072a49f Do not propagate reserved labels from image configs
  • vendor: golang.org/x/crypto v0.53.0 (#13607)
    • cfea2c141 [release/2.2] vendor: golang.org/x/crypto v0.53.0
  • update runc binary to v1.3.6 (#13606)
  • update go to 1.26.4/1.25.11 (#13577)
  • Configure udevd children-max for root-test (#13567)
    • 2b7dfbd7f Configure udevd children-max for root-test
  • Clean up disk space in node e2e workflow (#13548)
    • 1500e586f Clean up disk space in node e2e workflow
  • contrib/checkpoint: increase timeouts to 30s (#13460)
    • 9991e944e contrib/checkpoint: increase timeouts to 30s
  • release: don't mark 2.2 releases as latest (#13458)
    • 55a1f85d5 release: don't mark 2.2 releases as latest
Dependency Changes
  • golang.org/x/crypto v0.45.0 -> v0.53.0
  • golang.org/x/mod v0.29.0 -> v0.36.0
  • golang.org/x/net v0.47.0 -> v0.55.0
  • golang.org/x/sync v0.18.0 -> v0.21.0
  • golang.org/x/sys v0.38.0 -> v0.46.0
  • golang.org/x/term v0.37.0 -> v0.44.0
  • golang.org/x/text v0.31.0 -> v0.38.0

Previous release can be found at v2.2.4

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc and CNI plugins from their official sites too.

See also the Getting Started documentation.

View originalPermalink
How v2.2.5 went
View all

Discussion