RATATOSKRATATOSK
Sign in

containerd

v2.0.12Kubernetes Core
Sep 4, 2026

ACTION 2CHECK 1OTHER 6

A security-focused maintenance release fixes two disclosed vulnerabilities, changes the Windows logging default, and hardens registry fetching. It also includes correctness and performance fixes.

Action needed (2)

Check if affected (1)

  • breakingThe ScrubLogs Windows default

    Applies if you run containerd on Windows.

    ScrubLogs is used by default on Windows.

All 6 other recorded changesvalue changes 5 · additions 1

value changes (5)

  • * [eebea8c4c](https://github.com/containerd/containerd/commit/eebea8c4c912f44b656c8295c9e6607a19b76650) cri: cancel ExecSync IO drain on context cancellation
  • * [6c060c952](https://github.com/containerd/containerd/commit/6c060c9525bd53ce91adc3e1736ab2017bcc689f) archive: skip redundant opaque whiteout walks
  • * Set SystemTemp env var to config temp on Windows ([#14100](https://github.com/containerd/containerd/pull/14100)) * [56058341c](https://github.com/containerd/containerd/commit/56058341cb9f21ffe11b1d81099889d39c8e280e) Set SystemTemp env var to config temp on Windows
  • * docker fetcher: strip sensitive headers on descriptor URLs ([#14045](https://github.com/containerd/containerd/pull/14045)) * [88c95d56d](https://github.com/containerd/containerd/commit/88c95d56da275becf89bab5b373fbfc080231e49) core/remotes/docker: normalize descriptor URL origins * [7711c3d21](https://github.com/containerd/containerd/commit/7711c3d2188999822928251e154b8570ae9a078d) core/remotes/docker: strip sensitive headers on desc.urls fetch
  • * remotes: surface OCI error body on HEAD 403 via GET fallback ([#13749](https://github.com/containerd/containerd/pull/13749)) * [71a73c8a0](https://github.com/containerd/containerd/commit/71a73c8a0f3818e30d873e645b0335e4aa7913ba) remotes: surface OCI error body on HEAD 403 via GET fallback

additions (1)

  • add --scrub-logs flag for Windows
Add containerd to your stack

A weekly email arrives when a release needs action. Like the security patches and breaking changes in this release.

Add to stack