Skip to content

chore(deps): update dependency containerd/containerd to v2.3.4 - #179

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/containerd-containerd-2.x
Open

chore(deps): update dependency containerd/containerd to v2.3.4#179
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/containerd-containerd-2.x

Conversation

@renovate

@renovate renovate Bot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
containerd/containerd patch 2.3.12.3.4

Release Notes

containerd/containerd (containerd/containerd)

v2.3.4: containerd 2.3.4

Compare Source

Welcome to the v2.3.4 release of containerd!

The fourth patch release for containerd 2.3 contains various fixes and updates.

Highlights
Container Runtime Interface (CRI)
  • Disable checkpoint restore in CreateContainer by default, requiring the enable_experimental_restore_via_create configuration option to enable (#​13913)
  • Set default runtimeFeatures.UserNamespacesHostNetwork to true in CRI (#​13914)
  • Deprecate checkpoint restore in CreateContainer (#​13868)
  • Support non-UTF-8 binary environment variable values in CRI (#​13454)
  • Enable OCI runtime feature introspection for non-runc runtimes in CRI (#​13778)
  • Disable checkpoint restore codepaths when CRIU is not installed and add enable_criu configuration option (#​13734)
  • Normalize sandbox image references in CRI to resolve images without domain prefixes (#​13759)
Node Resource Interface (NRI)
  • Emit deprecation warnings for plugins using deprecated NRI interfaces (#​13935)
Runtime
  • Enable log scrubbing by default on Windows (#​13904)
  • Fix memory leak in OOM watcher map when stopping container monitoring (#​13870)
  • Avoid orphaning shims on transient errors when loading process IDs (#​13857)
  • Fix corruption of binary protobuf shim start responses caused by premature whitespace trimming (#​13803)
Snapshotters
  • Fix EROFS snapshotter dropping lower layers stacked above merged filesystem metadata (#​13876)
Breaking
  • Disable checkpoint restore in CreateContainer by default, requiring the enable_experimental_restore_via_create configuration option to enable (#​13913)
Deprecations
  • Deprecate checkpoint restore in CreateContainer (#​13868)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Maksym Pavlenko
  • Mike Brown
  • Akihiro Suda
  • Derek McGowan
  • Jordan Liggitt
  • Paweł Gronowski
  • Amir Alavi
  • Andrew Halaney
  • Bing Hongtao
  • Chris Henzie
  • Harshal Patel
  • Krisztian Litkey
  • Phil Estes
  • Wei Fu
  • ningmingxiao
Changes
35 commits

  • c1f5360ef Prepare release notes for v2.3.4
  • cri: disable restore in CreateContainer by default (#​13913)
    • 928c03c68 cri: disable restore in CreateContainer by default
  • nri,deprecation: record and emit warnings for NRI deprecations. (#​13935)
    • 5966e2edb nri,deprecation: emit warnings for old NRI plugins.
  • Set the default of runtimeFeatures.UserNamespacesHostNetwork to true (#​13914)
    • ab52c58f1 Set the default of runtimeFeatures.UserNamespacesHostNetwork to true
  • Use ScrubLogs by default on Windows (#​13904)
    • 0c255158a ctr: add --scrub-logs flag for Windows
    • 1c2b13dc9 cri/config: use ScrubLogs by default on Windows
  • snapshots/erofs: keep lowers stacked above a merged fsmeta (#​13876)
    • 0c511e068 snapshots/erofs: keep lowers stacked above a merged fsmeta
  • cri: deprecate restore in CreateContainer (#​13868)
    • dc98141df cri: deprecate restore in CreateContainer
  • internal/oom: Fix memory leak by removing watcher from map on Stop (#​13870)
    • 537d82d54 internal/oom: Fix memory leak by removing watcher from map on Stop
  • shim_load: Consider shim leaked only if we can't find pids (#​13857)
    • decf97a9c shim_load: Consider shim leaked only if we can't find pids
  • core/runtime/v2: Drop checkpointctl module dependency (#​13840)
    • 796f07dc8 core/runtime/v2: Drop checkpointctl module dependency
  • Handle []byte envvar value for CRI (#​13454)
    • 751fddddb Handle []byte envvar value
    • 0bce9060e update to v0.36.x kubernetes dependencies
  • fix(cri): introspect OCI runtime features for non-runc runtimes (#​13778)
    • 61a8f6f45 fix(cri): introspect OCI runtime features for non-runc runtimes
  • core/runtime/v2: Preserve protobuf shim response bytes (#​13803)
    • 1d28017be core/runtime/v2: Preserve protobuf shim response bytes
  • Disable checkpoint restore codepath when CRIU is not installed (#​13734)
    • 374091d67 github/workflows: install criu in node-e2e
    • db03e3968 cri: add enable_criu configuration option
    • dacd4c7d0 cri: validate CRIU availability and version early
  • ci: bound Go fuzzing by execution count (#​13785)
    • 890a9c86c ci: bound Go fuzzing by execution count
  • cri: auto-add prefix for pause image (#​13759)
    • 0b2f1d078 cri: auto-add prefix for pause image

Dependency Changes
  • k8s.io/api v0.36.0 -> v0.36.3
  • k8s.io/apimachinery v0.36.0 -> v0.36.3
  • k8s.io/client-go v0.36.0 -> v0.36.3
  • k8s.io/component-base v0.36.0 -> v0.36.3
  • k8s.io/cri-api v0.36.0 -> v0.36.3
  • k8s.io/cri-client v0.36.0 -> v0.36.3
  • k8s.io/cri-streaming v0.36.0 -> v0.36.3
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.3.3

Previous release can be found at v2.3.3

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.

v2.3.3: containerd 2.3.3

Compare Source

Welcome to the v2.3.3 release of containerd!

The third patch release for containerd 2.3 contains various fixes and updates.

Highlights
  • Set SystemTemp environment variable on Windows so temp directory overrides work for SYSTEM services (#​13694)
Container Runtime Interface (CRI)
  • Fix nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit (#​13697)
  • Reject CreateContainer calls when the target sandbox is not running (#​13668)
  • Ensure sandbox shutdown on RunPodSandbox hook failures to avoid mount leaks (#​13645)
Image Distribution
  • Surface OCI error bodies in registry 403 responses by falling back to GET requests (#​13738)
Snapshotters
  • Align default 4K mkfs block size for EROFS across all platforms (#​13632)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Maksym Pavlenko
  • Samuel Karp
  • Chris Henzie
  • Phil Estes
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Austin Vazquez
  • Chris Crone
  • Derek McGowan
  • Maksim An
  • crawfordxx
  • cshung
  • lauralorenz
Changes
14 commits

  • Prepare release notes for v2.3.3 (#​13750)
  • CI: migrate Vagrant to Lima (#​13744)
  • remotes: surface OCI error body in registry 4xx responses (#​13738)
    • 457fba3a3 remotes: surface OCI error body on HEAD 403 via GET fallback
  • Update go to 1.26.5 (#​13732)
  • ci: pin fog-json to resolve gem conflict (#​13711)
    • 5be0495df ci: pin fog-json to resolve gem conflict
  • Fix nil pointer dereference in NRI GetIPs (#​13697)
    • 36c713971 Fix nil pointer dereference in NRI GetIPs
  • Set SystemTemp env var to config temp on Windows (#​13694)
    • 26dce170d Set SystemTemp env var to config temp on Windows
  • update runhcs to v0.15.0-rc.3 (#​13693)
  • Update to current setup-go version (#​13686)
    • 3e97edeb7 Update to current setup-go version
  • cri: reject CreateContainer when sandbox is not running (#​13668)
    • 8856b0f9c cri: reject CreateContainer when sandbox is not running
  • update runhcs to v0.15.0-rc.2 (#​13666)
  • test: fix flaky image timestamp check on coarse clocks (#​13643)
    • 168d56783 test: fix flaky image timestamp check on coarse clocks
  • Add defer in event of mid-function failures in RunPodSandbox to avoid mount leaks (#​13645)
    • d1db61db8 Add deferred call to ShutdownSandbox to avoid leaks
  • erofs: align default mkfs block size across platforms (#​13632)
    • 01b0f03f6 erofs: align default mkfs block size across platforms

Dependency Changes

This release has no dependency changes

Previous release can be found at v2.3.2

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.

v2.3.2: containerd 2.3.2

Compare Source

Welcome to the v2.3.2 release of containerd!

The second patch release for containerd 2.3 contains various fixes
and updates including security patches.

Security Updates
Highlights
  • Fix a data race when reading shim logs on Windows (#​13522)
Image Distribution
  • Allow the last host to retry on transient network errors (#​13591)
Runtime
  • Fix container startup failures caused by concurrent task RPC timeouts during slow container creation (#​13512)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akihiro Suda
  • Derek McGowan
  • Akhil Mohan
  • Austin Vazquez
  • Ben Cressey
  • Brian Goff
  • Maksym Pavlenko
  • Sebastiaan van Stijn
  • Sergey Kanzhelev
Changes
30 commits

  • Prepare release notes for v2.3.2 (#​13627)
    • fb8ca00b0 Prepare release notes for v2.3.2
    • 9c69960ba Merge commit from fork
    • 0f6251520 Merge commit from fork
    • 91d7471e2 cri: filter CDI annotations on checkpoint restore
    • 7c2e086bf Merge commit from fork
    • dae67765f cri: do not re-tag restored checkpoints
    • 94aa1e2c1 Merge commit from fork
    • 09599078f cri: make checkpoint restore robust to unexpected archive content
    • e1fdb8d22 Merge commit from fork
    • ff1d116ef Bound user-database file reads in openUserFile
    • d156e07cb Merge commit from fork
    • f99aad54a Do not propagate reserved labels from image configs
  • vendor: golang.org/x/crypto v0.53.0 (#​13608)
    • 0b9469501 [release/2.3] vendor: golang.org/x/crypto v0.53.0
  • resolver: retry on transient network errors (#​13591)
    • 983bbddc1 resolver: retry on transient network errors
  • update runc binary to v1.4.3 (#​13601)
  • update go to 1.26.4 (#​13580)
    • 8a49dfe85 update go to 1.26.4
    • 5aa6bb2b7 remove 1.26.2 from CI builds as it is not supported any longer due to the dependency
  • Configure udevd children-max for root-test (#​13568)
    • bfb8aebc0 Configure udevd children-max for root-test
  • core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read (#​13522)
    • 62ceafff0 core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read
  • runc-shim: don't hold the service lock across runc create (#​13512)
    • 9b0c0dc58 runc-shim: don't hold the service lock across runc create
  • contrib/checkpoint: increase timeouts to 30s (#​13459)
    • f588bc6fb contrib/checkpoint: increase timeouts to 30s

Dependency Changes
  • golang.org/x/crypto v0.49.0 -> v0.53.0
  • golang.org/x/mod v0.35.0 -> v0.36.0
  • golang.org/x/net v0.52.0 -> v0.55.0
  • golang.org/x/sync v0.20.0 -> v0.21.0
  • golang.org/x/sys v0.43.0 -> v0.46.0
  • golang.org/x/term v0.41.0 -> v0.44.0
  • golang.org/x/text v0.35.0 -> v0.38.0

Previous release can be found at v2.3.1

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/containerd-containerd-2.x branch from a18c07f to 5ddaf41 Compare July 10, 2026 01:34
@renovate renovate Bot changed the title chore(deps): update dependency containerd/containerd to v2.3.2 chore(deps): update dependency containerd/containerd to v2.3.3 Jul 10, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/containerd-containerd-2.x branch from 5ddaf41 to 51a4ca9 Compare August 12, 2026 22:09
@renovate renovate Bot changed the title chore(deps): update dependency containerd/containerd to v2.3.3 chore(deps): update dependency containerd/containerd to v2.3.4 Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants