Skip to content

dependabot(deps): bump github.com/opencontainers/runc from 1.4.3 to 1.5.1 in /images/capi/packer/config/kubernetes-version-dependencies/latest - #2142

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/images/capi/packer/config/kubernetes-version-dependencies/latest/github.com/opencontainers/runc-1.5.1
Open

dependabot(deps): bump github.com/opencontainers/runc from 1.4.3 to 1.5.1 in /images/capi/packer/config/kubernetes-version-dependencies/latest#2142
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/images/capi/packer/config/kubernetes-version-dependencies/latest/github.com/opencontainers/runc-1.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/opencontainers/runc from 1.4.3 to 1.5.1.

Release notes

Sourced from github.com/opencontainers/runc's releases.

runc v1.5.1 -- "El lujo es vulgaridad, dijo, y me conquistó."

This is the first patch release in the 1.5.z release series of runc, and primarily includes a fix for a serious regression on Ubuntu 20.04 kernels.

Fixed

  • There was a regression reported in with the maskPaths optimisation added in 1.5.0-rc.3 (#5275). On Ubuntu Focal (20.04), attempts to mount tmpfs with the nr_inodes=1 option will fail due to a downstream kernel patch (ironically originating from AUFS). We now have a fallback path using nr_inodes=2 instead if the operation fails. (#5348, #5358, #5359)
  • Properly handle EINVAL for seccomp SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV when trying to rewrite the filter. This appears to only happen if you compile runc with libseccomp >= 2.6.0 and then run it with an < 2.6.0 libseccomp. (#5347, #5354)

Static Linking Notices

The runc binaries distributed with this release are statically linked with the following GNU LGPL-2.1 licensed libraries, with runc acting as a "work that uses the Library":

Similarly, the runc binaries distributed with this release are also statically linked with the following MPLv2 licensed libraries, with runc acting as a "Larger Work":

The versions of these libraries were not modified from their upstream versions, but in order to comply with their corresponding licenses, we have attached the complete source code for those libraries which (when combined with the attached runc source code) may be used to exercise your rights under their respective licenses.

However, we strongly suggest that you make use of your distribution's packages or download them from the authoritative upstream sources, especially since these libraries are related to the security of your containers.


Thanks to the following contributors who made this release possible:

... (truncated)

Changelog

Sourced from github.com/opencontainers/runc's changelog.

[1.5.1] - 2026-07-14

El lujo es vulgaridad, dijo, y me conquistó.

Fixed

  • There was a regression reported in with the maskPaths optimisation added in 1.5.0-rc.3 (#5275). On Ubuntu Focal (20.04), attempts to mount tmpfs with the nr_inodes=1 option will fail due to a downstream kernel patch (ironically originating from AUFS). We now have a fallback path using nr_inodes=2 instead if the operation fails. (#5348, #5358, #5359)
  • Properly handle EINVAL for seccomp SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV when trying to rewrite the filter. This appears to only happen if you compile runc with libseccomp >= 2.6.0 and then run it with an < 2.6.0 libseccomp. (#5347, #5354)

[1.5.0] - 2026-06-19

Why do we even have that lever?!

Added

  • runc version and runc features now provide version information about libpathrs (when runc is built with the libpathrs build tag). (#5291, #5328)

Fixed

  • Since runc 1.3.0, the org.opencontainers.runc.version annotation included in runc features contained an extraneous \n, possibly causing issues with tools that parse the output. It is now properly stripped. (#5329, #5330, #5331, #5335)

Changed

  • runc (when built with the libpathrs build tag) now depends on libpathrs v0.2.5 or later, and attempting to build with older versions will cause compilation errors. (#5291, #5328)
  • Switched to go-criu v8.3.0, which reduces our binary size from ~16MB to ~14MB. (#5312, #5326)

[1.5.0-rc.3] - 2026-06-13

The best way to get a drink out of a Vogon is to stick your finger down his throat.

Security

This release includes a fix for the following low-severity security issue:

  • [CVE-2026-41579][] allowed a malicious image with a /dev symlink to have limited write access to the host filesystem in ways that our analysis indicates was too limited to be problematic in practice. This bug was very

... (truncated)

Commits
  • 8f2685a VERSION: release v1.5.1
  • 1846115 Merge pull request #5357 from rata/1.5-fix-CI
  • 62a3230 tests/integration: Simplify delete_netns()
  • 0a4cc77 tests: Clarify the interface might not be on the host
  • cc0c204 tests: Unset ns_path when deleting the netns
  • 591db7d tests/checkpoint.bats: Move netdev code outside of setup()
  • 5514481 tests: fix dummy0 flakes
  • 3ba5ef1 Merge pull request #5359 from lifubang/backport-5358-to-release-1.5
  • 6dc94f9 libct: retry with nr_inodes=2 to fix Focal mount errors
  • 79cf0d6 Merge pull request #5354 from lifubang/backport-5347-to-release-1.5
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/opencontainers/runc](https://github.com/opencontainers/runc) from 1.4.3 to 1.5.1.
- [Release notes](https://github.com/opencontainers/runc/releases)
- [Changelog](https://github.com/opencontainers/runc/blob/v1.5.1/CHANGELOG.md)
- [Commits](opencontainers/runc@v1.4.3...v1.5.1)

---
updated-dependencies:
- dependency-name: github.com/opencontainers/runc
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesn't merit a release note. labels Aug 21, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Aug 21, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign jsturtevant for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesn't merit a release note. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants