* [`4864b1814`](https://github.com/containerd/containerd/commit/4864b18144ed746eda776112370bf83121348275) Prepare release notes for v2.2.8 * [`3458b7fd3`](https://github.com/containerd/containerd/commit/3458b7fd367be3981b57262c5f0c267bf0570a71) Merge commit from fork * [`22ccf4314`](https://github.com/containerd/containerd/commit/22ccf4314d1fe0834f8e28f10d37d5305ef9880c) cri: cancel ExecSync IO drain on context cancellation * [`2bf01ce17`](https://github.com/containerd/containerd/commit/2bf01ce17baa2cc3904f377f2cc9d815631ac704) Merge commit from fork * [`45166eb82`](https://github.com/containerd/containerd/commit/45166eb828c9f8605db44299836a87b78bda701b) archive: skip redundant opaque whiteout walks * Set SystemTemp env var to config temp on Windows ([#14102](https://github.com/containerd/containerd/pull/14102)) * [`2c722ad04`](https://github.com/containerd/containerd/commit/2c722ad0418df21ff173c3f54dd3dd4713302cd8) Set SystemTemp env var to config temp on Windows * pkg/oci: resolve rootfs symlinks for user lookup ([#14005](https://github.com/containerd/containerd/pull/14005)) * [`196664bc0`](https://github.com/containerd/containerd/commit/196664bc020998bf20f3d96708edcaacc5c891d0) pkg/oci: resolve rootfs symlinks for user lookup * docker fetcher: strip sensitive headers on descriptor URLs ([#14044](https://github.com/containerd/containerd/pull/14044)) * [`6da9d9528`](https://github.com/containerd/containerd/commit/6da9d9528820212d3e0d357738acff1b34ee4188) core/remotes/docker: normalize descriptor URL origins * [`4f7851699`](https://github.com/containerd/containerd/commit/4f7851699263c4b7fff39e80af3464ad07d5bdc1) core/remotes/docker: strip sensitive headers on desc.urls fetch * snapshots/erofs: protect snapshot staging from cleanup ([#13950](https://github.com/containerd/containerd/pull/13950)) * [`f7075a224`](https://github.com/containerd/containerd/commit/f7075a224aa2f17d5e4afcc3026a6ac644b5c93b) snapshots/erofs: protect snapshot staging from cleanup