Release v0.7.0.
* Port runc security patches for CVE-2025-3133, CVE-2025-52881, CVE-52565. * Support volatile overlayfs remounting. * Add features command to sysbox-runc. * Enable newer versions of runc to run inside Sysbox containers properly by trapping openat2 system call to allow access to sysbox-fs mounts under /proc and /sys. * sysbox-deploy-k8s: add support for k8s v1.33, v1.34, and v1.35. Deprecate support for v1.29 to v1.31. * sysbox-deploy-k8s: enable compatibility with K8s user-namespaces (requires containerd v2.0.5+ or CRI-O). * sysbox-deploy-k8s: don't install CRI-O when K8s cluster has containerd 2.0.5+. * Update docs to indicate support for K8s user-namespaces (requires `hostUsers: false` directive in pod spec). Signed-off-by: Cesar Talledo <cesar.talledo@docker.com>
C
Cesar Talledo committed
9774489150b8c88874867a67f00120658fb02c24
Parent: b4835fa