RATATOSKRATATOSK
Sign in

containerd

v1.7.35Kubernetes Core
Sep 4, 2026

ACTION 2CHECK 1OTHER 5

A security-focused maintenance release with fixes for vulnerabilities and changes to image fetching and Windows log handling. Runtime and performance improvements are also included.

Action needed (2)

Check if affected (1)

  • breakingThe ScrubLogs default on Windows

    Applies if you run on Windows.

    Windows now uses ScrubLogs by default.

All 5 other recorded changesvalue changes 4 · additions 1

value changes (4)

  • * Apply hardening to strip sensitive authentication headers when fetching descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046))
  • * [5a2a3a759](https://github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc20890daf6d81) cri: cancel ExecSync IO drain on context cancellation
  • * [9205b1903](https://github.com/containerd/containerd/commit/9205b1903b1336d77864ee658a43b7989f56d13e) archive: skip redundant opaque whiteout walks
  • * docker fetcher: strip sensitive headers on descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046)) * [b01d66349](https://github.com/containerd/containerd/commit/b01d66349d39f72a9c56696741913bdc5f4332cd) core/remotes/docker: normalize descriptor URL origins * [b5d936dca](https://github.com/containerd/containerd/commit/b5d936dca5e7c5980f2ed0f5114a388ad916a328) core/remotes/docker: strip sensitive headers on desc.urls fetch

additions (1)

  • * [cff94ea40](https://github.com/containerd/containerd/commit/cff94ea40f3959d5f77451b9d72365db44e8d153) ctr: add --scrub-logs flag for Windows
Add containerd to your stack

A weekly email arrives when a release needs action. Like the security patches and breaking changes in this release.

Add to stack