Releases: kairos-io/kairos
Releases · kairos-io/kairos
Release list
v4.2.0-rc2
What's Changed
- fix: add renovate regex to match auroraboot_version by @wcrum in #4295
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.26.2 by @renovate[bot] in #4273
- ⬆️ Update google/osv-scanner-action action to v2.5.0 - autoclosed by @renovate[bot] in #4289
- ci: gate releases on a vulnerability scan of the shipped bundle by @mauro-agent in #4300
- ci: bump the factory pin to v1.3.0 by @mauro-agent in #4311
- ci: bump the factory pin to v1.4.0 and drop the Jetson SBOM attestation by @mauro-agent in #4315
New Contributors
- @wcrum made their first contribution in #4295
- @mauro-agent made their first contribution in #4300
Full Changelog: v4.2.0-rc1...v4.2.0-rc2
v4.2.0-rc1
What's Changed
- ⬆️ Update actions/checkout action to v7 by @renovate[bot] in #4174
- ⬆️ Update kairos-io/kairos-factory-action action to v1.1.3 by @renovate[bot] in #4173
- ⬆️ Update module github.com/onsi/ginkgo/v2 to v2.32.0 by @renovate[bot] in #4179
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.24.0 by @renovate[bot] in #4168
- ⬆️ Update module github.com/mudler/edgevpn to v0.35.2 by @renovate[bot] in #4077
- ⬆️ Update module github.com/onsi/gomega to v1.42.1 by @renovate[bot] in #4186
- ⬆️ Update quay.io/kairos/kairos-init Docker tag to v0.15.0 by @renovate[bot] in #4187
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.25.0 by @renovate[bot] in #4197
- ⬆️ Update actions/setup-go action to v6.5.0 by @renovate[bot] in #4193
- ⬆️ Update aws-actions/configure-aws-credentials digest to 254c19b by @renovate[bot] in #4199
- ⬆️ Update quay.io/kairos/kairos-init Docker tag to v0.15.1 by @renovate[bot] in #4220
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.25.1 by @renovate[bot] in #4219
- ⬆️ Update quay.io/kairos/kairos-init Docker tag to v0.15.2 by @renovate[bot] in #4226
- ⬆️ Update docker/build-push-action action to v7.3.0 by @renovate[bot] in #4209
- ⬆️ Update docker/login-action digest to c99871d by @renovate[bot] in #4210
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.25.2 by @renovate[bot] in #4225
- ⬆️ Update aws-actions/configure-aws-credentials digest to 517a711 by @renovate[bot] in #4223
- ⬆️ Update docker/setup-buildx-action digest to bb05f3f by @renovate[bot] in #4211
- ⬆️ Update module github.com/mudler/edgevpn to v0.35.3 by @renovate[bot] in #4224
- ⬆️ Update actions/stale action to v10.4.0 by @renovate[bot] in #4236
- chore: bump kairos-init to v0.16.1 by @mauromorales in #4238
- ⬆️ Update actions/setup-go action to v7 by @renovate[bot] in #4248
- ⬆️ Update module github.com/diskfs/go-diskfs to v1.9.4 by @renovate[bot] in #4249
- ⬆️ Update ossf/scorecard-action action to v2.4.4 by @renovate[bot] in #4262
- Add e2e test for kairos-agent kcrypt subcommands by @jimmykarily in #4274
- docs: link CLOTributor for contributors seeking issues by @thev1ndu in #4280
New Contributors
Full Changelog: v4.1.2...v4.2.0-rc1
v4.1.2
What's Changed
- Fix release notes diff failing on releases API timeout by @jimmykarily in #4149
- Fix release notes diff 504 by @jimmykarily in #4150
- Fix backtick escaping in workflow summary by @jimmykarily in #4151
- ⬆️ Update actions/stale action to v10.3.0 by @renovate[bot] in #4129
- docs: fix non-HWE example path in README by @jimmykarily in #4142
- ⬆️ Update actions/checkout action to v6.0.3 by @renovate[bot] in #4124
- ⬆️ Update google/osv-scanner-action action to v2.3.8 by @renovate[bot] in #4071
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.20.1 by @renovate[bot] in #4079
- ⬆️ Update robinraju/release-downloader action to v1.13 by @renovate[bot] in #4080
- ⬆️ Update module github.com/mudler/go-processmanager to v0.1.1 by @renovate[bot] in #4072
- ⬆️ Update module github.com/diskfs/go-diskfs to v1.9.2 by @renovate[bot] in #4074
- ⬆️ Update docker/login-action digest to 4907a6d by @renovate[bot] in #4070
- ⬆️ Update docker/build-push-action action to v7.2.0 by @renovate[bot] in #4154
- ⬆️ Update aws-actions/configure-aws-credentials digest to e7f100c by @renovate[bot] in #4069
- ⬆️ Update module github.com/onsi/ginkgo/v2 to v2.31.0 by @renovate[bot] in #4155
- ⬆️ Update actions/github-script action to v9 by @renovate[bot] in #4157
- ⬆️ Update azure/login action to v3 by @renovate[bot] in #4159
- ⬆️ Update azure/cli action to v3 by @renovate[bot] in #4158
- ⬆️ Update module github.com/onsi/gomega to v1.42.0 by @renovate[bot] in #4156
- ⬆️ Update docker/setup-buildx-action action to v4 by @renovate[bot] in #4160
- ⬆️ Update docker/login-action digest to 650006c by @renovate[bot] in #4163
- ⬆️ Update module github.com/diskfs/go-diskfs to v1.9.3 by @renovate[bot] in #4164
- ⬆️ Update quay.io/kairos/auroraboot Docker tag to v0.23.0 by @renovate[bot] in #4165
- chore: bump auroraboot to v0.23.0 across all workflows by @Copilot in #4166
- Bump workflow hadron and hadron-trusted image references to v0.4.0 by @Copilot in #4162
Full Changelog: v4.1.1...v4.1.2
Changes since previous version (v4.1.1)
Kairos changes
- Fix release notes diff failing on releases API timeout by @jimmykarily in #4149
- Fix release notes diff 504 by @jimmykarily in #4150
- Fix backtick escaping in workflow summary by @jimmykarily in #4151
- docs: fix non-HWE example path in README by @jimmykarily in #4142
- chore: bump auroraboot to v0.23.0 across all workflows by @Copilot in #4166
- Bump workflow hadron and hadron-trusted image references to v0.4.0 by @Copilot in #4162
kairos-init changes
- Version: v0.14.6 -> v0.14.6
- No changes
Immucore changes
- No changes (v0.16.2)
kairos-agent changes
- No changes (v2.29.4)
kairos-sdk changes
- No changes (v0.22.0)
kcrypt-discovery-challenger changes
- No changes (v0.13.2)
provider-kairos changes
- No changes (v2.16.1)
edgevpn changes
- No changes (v0.35.2)
entities changes
- No changes (v0.8.3)
go-pluggable changes
- No changes (v0.0.0-20230126220627-7710299a0ae5)
yip changes
- No changes (v1.24.0)
xpasswd changes
- No changes (v0.4.7)
v4.1.1
Warning
Security Notice: The standard images in this release contain known CVEs from upstream components (k3s and k0s). These vulnerabilities originate from the Kubernetes distribution binaries and are outside our control. Please review the security scan results before deploying to production.
What's Changed
- docs: fix stale governance links and ubuntu 24.04 fips readme by @immanuwell in #4076
- Update hadron image references to v0.2.1 by @Copilot in #4087
- ⬆️ Update quay.io/kairos/kairos-init Docker tag to v0.13.1 by @renovate[bot] in #4066
- Bump hadron to v0.3.0 by @jimmykarily in #4103
- ⬆️ Update quay.io/kairos/kairos-init Docker tag to v0.14.0 by @renovate[bot] in #4118
- Don't enforce security scans on master by @jimmykarily in #4127
New Contributors
- @immanuwell made their first contribution in #4076
Full Changelog: v4.1.0...v4.1.1
Changes since previous version (v4.1.0)
Kairos changes
- docs: fix stale governance links and ubuntu 24.04 fips readme by @immanuwell in #4076
- Update hadron image references to v0.2.1 by @Copilot in #4087
- Bump hadron to v0.3.0 by @jimmykarily in #4103
- Don't refer to non-existing artifacts (hardcoded by mistake) by @jimmykarily in bee8fbb
- Don't hardcode tags in public cloud image workflow by @jimmykarily in 85b76a9
- Fix backup header on GCP after resizing by @jimmykarily in d757c3e
- Fix gcloud image creation by @jimmykarily in 0e51b47
- Bump kairos-init to v0.14.3 by @jimmykarily in 9679e68
- Bump kairos-init (again) by @jimmykarily in 57350d8
- Bump kairos-init by @jimmykarily in af74352
- Don't enforce security scans on master by @jimmykarily in #4127
- Don't block releases on CVEs of k3s/k0s (on sarif scan) by @jimmykarily in #4133
- Don't block master builds on grype reports by @jimmykarily in #4145
- Release scan report only by @jimmykarily in #4146
- Release scan report only by @jimmykarily in #4147
kairos-init changes
- Version: v0.13.0 -> v0.14.6
- riscv64: UPX overrides and Fedora grub EFI packages by @mauromorales in #352
- Disable systemd-networkd in sles5.5 too by @jimmykarily in #353
- feat: Enable VMware tools for systemd and OpenRC by @Itxaka in #354
- Fix newline at end of 26_vm.yaml by @Itxaka in c2eda6d
- fix: Update model detection for Thor by @Itxaka in #361
- Configure Renovate to update only semver-tagged Hadron images in GitHub workflows by @Copilot in #362
- Bump kcrypt-discovery-challenger to v0.13.2 by @mauromorales in #367
- Bump deps by @jimmykarily in 7274d1e
- chore(deps): bump x/net and go to fix CVEs by @mauromorales in #370
- Add retry flags to curl and show errors by @jimmykarily in #371
- Bump edgevpn to v0.35.2 by @jimmykarily in 5c56c85
Immucore changes
- Version: v0.16.1 -> v0.16.2
- fix(deps): update golang.org/x dependencies by @Itxaka in e899765
- Potential fix for code scanning alert no. 186: Workflow does not contain permissions by @Itxaka in #566
- Potential fix for code scanning alert no. 187: Workflow does not contain permissions by @Itxaka in #565
- Potential fix for code scanning alert no. 188: Workflow does not contain permissions by @Itxaka in #564
kairos-agent changes
- Version: v2.29.1 -> v2.29.4
- fix: support riscv64 platform detection by @mauromorales in #1216
- Update renovate.json configuration by @Itxaka in 4457477
- fix(grub): skip shim copy on riscv64 EFI install by @mauromorales in #1230
- fix(deps): bump golang.org/x/image to v0.41.0 by @mauromorales in #1231
kairos-sdk changes
- Version: v0.20.0 -> v0.22.0
- Remove Go version constraint from renovate.json by @Itxaka in ce71ab1
- chore: bump Go toolchain to 1.26.3 for stdlib CVE remediation by @Copilot in #763
- Add riscv64 platform support by @mauromorales in #762
- Support insecure registries when fetching images by @jimmykarily in #769
- Bump go and golang.org/x/net to fix CVEs reported by OSV scanner by @jimmykarily in #772
kcrypt-discovery-challenger changes
- Version: v0.13.1 -> v0.13.2
- fix(deps): address Go security advisories by @mauromorales in #226
provider-kairos changes
- Version: v2.16.0 -> v2.16.1
- feat(role): make auto role-coordination resilient to lost ledger writes by @mudler in #909
- feat(cli): allow --api and --network-id to be set via environment by @mudler in #913
- feat(bootstrap): honor EDGEVPN_API env for the bootstrap event handler by @mudler in #914
edgevpn changes
- Version: v0.32.2 -> v0.35.2
- fix(blockchain): resolve equal-index ledger split-brain with a deterministic tie-break by @mudler in #1011
- Support android interfaces by @jimmykarily in #1008
- feat: improve pubsub reliability and NAT detection for small clusters by @mudler in #1014
- feat: improve pubsub reliability and NAT detection for small clusters by @mudler in #1020
- deps: use mudler/go-libp2p-pubsub fork to enable pubsub over relayed conns by @mudler in #1027
- feat(api): harden local API unix socket listener by @mudler in #1028
- feat(relay): expose circuit-v2 relay-service resource knobs by @mudler in #1031
- feat(relay): NetworkOnly ACL — gate reservations on cluster membership by @mudler in #1032
- Fix GitHub Pages CI by migrating docs build to Hugo Modules by @Copilot in #1033
- feat(blockchain): authenticated, per-owner ledger entries (experimental) by @mudler in #1034
- Bump go toolchain and crypto to get rid of security reports by @jimmykarily in #1035
- Bump golang.org/x/net to fix GO-2026-5026 by @jimmykarily in #1039
entities changes
- Version: v0.8.3-0.20260109121712-af3b96567af9 -> v0.8.3
- fix: Update Go module dependencies and improve shadow handling by @Itxaka in #20
go-pluggable changes
- No changes (v0.0.0-20230126220627-7710299a0ae5)
yip changes
- Version: v1.23.6 -> v1.24.0
- chore: Update Go module dependencies by @Itxaka in #284
- feat: Add support for noformat partitions by @Itxaka in #292
xpasswd changes
- No changes (v0.4.7)
v4.1.0
Kairos changes
- Automate release notes diff changes by @mauromorales in #4022
- Make the gcp upload script idempotent by @jimmykarily in #4034
- Timeout the import task after 60 retries and print out what's wrong by @jimmykarily in #4035
- Print import error by @jimmykarily in #4036
- add adopter application form by @mauromorales in #4037
- Do not block release on k0s/k3s and add a release note by @mauromorales in #4052
- feat: bump hadron base image to v0.2.0 by @mauromorales in #4067
- ⬆️ Update GitHub Actions to latest versions by @mauromorales in #4068
- Bump kairos-init to v0.13.0 by @jimmykarily in 926d4f8
kairos-init changes
- Version: v0.8.4 -> v0.13.0
- fix: Adjust network module detection for RHEL 9.0 by @Itxaka in #297
- Add support for ubuntu 26.04 by @liyimeng in #304
- fix: Generate machine-id in recovery mode for openrc systems by @jimmykarily in #306
- fix(grub): properly detach loop before trying to mount by @mudler in #316
- fix: Add Oracle Linux to the RHEL-family like OnlyifOS and only_os regexes by @hung-do-nl in #311
- feat: Update console settings for Thor model by @Itxaka in #312
- feat: validate --model flag against supported models list by @Itxaka in #317
- feat: Update Dockerfile and Makefile for RISC-V support by @Itxaka in #318
- fix(install): try epel-release package first on RHEL, fall back to URL by @imusmanmalik in #327
- Bump kairos agent by @jimmykarily in #330
- Bump various dependencies combining multiple renovate PRs by @jimmykarily in #332
- Bump immucore to v0.14.1 and kcrypt-discovery-challenger to v0.13.1 by @mauromorales in #335
- fix: wrap loopback -d loop0 with conditional to avoid errors on fresh installs by @Copilot in #336
- Add Fedora and Hadron RISC-V test images by @mauromorales in #323
- Harden GitHub Actions workflows with least-privilege permissions by @Copilot in #342
- Bump provider-kairos to v2.15.1 and hadron to v0.2.0 by @mauromorales in #343
- bump kairos-agent version by @jimmykarily in 0963a03
Immucore changes
- Version: v0.13.1 -> v0.16.1
- Bump yip to v1.23.3 by @jimmykarily in #550
- Replace go-kdetect with mauromorales fork by @mauromorales in 0c4cf7b
- Revert "Replace go-kdetect with mauromorales fork" by @mauromorales in e282bdc
- feat: Add riscv64 architecture support by @Itxaka in #552
- chore: bump Go to 1.26.2 by @mauromorales in #557
- feat: Add TPM kernel module support during uki boot by @Itxaka in #555
- fix: Correct typos in kernel driver constants by @Itxaka in #559
- fix(deps): bump kairos-sdk to v0.20.0 and ghw to v0.24.0 by @jimmykarily in b1ba379
- Revert "fix(deps): bump kairos-sdk to v0.20.0 and ghw to v0.24.0" by @jimmykarily in 7ffd521
kairos-agent changes
- Version: v2.27.0 -> v2.29.1
- feat: Add riscv64 architecture support in goreleaser config by @Itxaka in #1175
- Bump yip to v1.23.3 by @jimmykarily in #1183
- feat: add phone-home feature by @mudler in #1179
- Bump deps by @jimmykarily in #1197
- feat: Enhance systemd-boot support with assessment suffix handling by @Itxaka in #1193
- Use yip helper to resolve
script://disk path by @jimmykarily in #1202 - Bump go and remove relic osv scanner ignore by @jimmykarily in 7c55561
kairos-sdk changes
- Version: v0.17.0 -> v0.20.0
- docs: Update comments for EFI grub and shim file paths by @Itxaka in #704
- Update renovate_auto.yml by @Itxaka in 5e3b177
- fix: rename logger file so !windows constraint is actually applied by @mvegter in #719
- Don't shadow errors (not ignore them) by @jimmykarily in #735
- fix(deps): replace github.com/docker/docker with moby split modules by @jimmykarily in #747
- Bump yip to v1.23.4 by @jimmykarily in a62bbb8
- Update json schema for config for the new
script://disk schema by @jimmykarily in #750 - Bump deps (combining multiple renovate PRs) by @jimmykarily in c2b489c
- Replace Earthly with Make target and respect sheband in bundles run.sh by @jimmykarily in #755
kcrypt-discovery-challenger changes
- Version: v0.12.2 -> v0.13.1
- feat: Add riscv64 architecture support by @Itxaka in #201
- chore: upgrade Go to 1.26.2 by @mauromorales in #206
provider-kairos changes
- Version: v2.14.2 -> v2.16.0
- bump github.com/mudler/edgevpn v0.31.1 → v0.32.0 by @Copilot in #886
- feat: Add riscv64 architecture support by @Itxaka in #888
- chore: bump Go to 1.26.3 and fix vulnerable dependencies by @mauromorales in #897
- fix deep copy of kubevip by @wcrum in #852
edgevpn changes
- Version: v0.31.1 -> v0.32.2
- Fix typo in architecture documentation (randevous -> rendezvous) by @qjoly in #953
- Enhance README with EdgeVPN library example by @mudler in cda4fd8
- Fix LocalAI GitHub link in README by @mudler in f0a047e
- Add example usage of Kairos project in README by @mudler in ddbcbac
- Rename c3os to kairos in Readme by @jasperdekeuk in #963
- chore: bump go directive in go.mod to 1.26 by @Copilot in #998
- feat: Add riscv64 architecture support by @Itxaka in #1007
entities changes
- No changes (v0.8.3-0.20260109121712-af3b96567af9)
go-pluggable changes
- No changes (v0.0.0-20230126220627-7710299a0ae5)
yip changes
- Version: v1.23.1 -> v1.23.6
- fix: correct bytes-vs-sectors unit mismatch in layout partition expansion by @imusmanmalik in #257
- Handle more than just nvme devices. by @gnoejuan in #261
- fix: upgrade go-containerregistry to v0.21.5 to drop docker/docker dep by @jimmykarily in #264
- Bump deps (combining renovate bumps in one PR) by @jimmykarily in #267
- 391 flexible disks by @jimmykarily in #273
- Remove Go version constraints from renovate.json by @Itxaka in #277
- fix(user): preserve /etc/shadow password-aging fields on password change by @localai-bot in #282
xpasswd changes
- Version: v0.4.1 -> v0.4.7
- Fix release workflow to use correct Go version by @mauromorales in #46
Full Changelog: v4.0.3...v4.1.0
v4.1.0-rc1
What's Changed
- Automate release notes diff changes by @mauromorales in #4022
- Make the gcp upload script idempotent by @jimmykarily in #4034
- Timeout the import task after 60 retries and print out what's wrong by @jimmykarily in #4035
- Print import error by @jimmykarily in #4036
- add adopter application form by @mauromorales in #4037
- Do not block release on k0s/k3s and add a release note by @mauromorales in #4052
- feat: bump hadron base image to v0.2.0 by @mauromorales in #4067
- ⬆️ Pin actions/checkout action to 34e1148 by @renovate[bot] in #4023
- ⬆️ Update google/osv-scanner-action action to v2.3.3 by @renovate[bot] in #4017
- ⬆️ Update golang Docker tag to v1.26 by @renovate[bot] in #3968
- ⬆️ Update aws-actions/configure-aws-credentials action to v6 by @renovate[bot] in #3913
- ⬆️ Update GitHub Actions to latest versions by @mauromorales in #4068
Full Changelog: v4.0.3...v4.1.0-rc1
v4.0.3
Kairos changes
Full Changelog: v4.0.2...v4.0.3
kairos-init changes
- Version: v0.7.3 -> v0.8.4
- fix: Use chronyd for time sync on RHEL family and Fedora by @mvegter in #289
- Bump yip for better logging of command errors by @jimmykarily in #290
- feat: Update service management for SUSE Micro by @Itxaka in #292
- fix: normalize openSUSE regex matching and fix malformed SUSE alternation by @mvegter in #294
- chore: Remove policycoreutils from installation steps by @Itxaka in #295
- feat: Skip UPX tests in Dockerfile by @Itxaka in #296
- feat: Add systemd-resolved to enabled services by @Itxaka in #299
Immucore changes
- No changes (v0.13.1)
kairos-agent changes
- No changes (v2.27.0)
kairos-sdk changes
- No changes (v0.17.0)
kcrypt-discovery-challenger changes
- No changes (v0.12.2)
provider-kairos changes
- Version: v2.14.1 -> v2.14.2
- bump grpc to address GHSA-p77j-4mvh-x3m3 by @mauromorales in #880
edgevpn changes
- No changes (v0.31.1)
entities changes
- No changes (v0.8.3-0.20260109121712-af3b96567af9)
go-pluggable changes
- No changes (v0.0.0-20230126220627-7710299a0ae5)
yip changes
- Version: v1.23.0 -> v1.23.1
- When a command fails, include the command output in the error by @jimmykarily in #260
xpasswd changes
- No changes (v0.4.1)
v4.0.3-rc1
v4.0.2
Kairos v4.0.2 is aimed at addressing a CVE in Go previous to 1.26.1 plus bumping of some components and with that some new features which are mentioned below.
Kairos changes
- bump kairos-factor-action to v1.1.1 by @mauromorales in #4016
- Bump auroraboot to v0.19.4 by @mauromorales in #4019
kairos-init changes
- Version: v0.7.0 -> v0.7.3
- fix: parse ID_LIKE as space-separated list per os-release spec by @mvegter in #279
- feat: Update sysext and confext configuration by @Itxaka in #285
Immucore changes
- Version: v0.12.0 -> v0.13.1
- feat: Add support for confext extensions by @Itxaka in #547
- feat: Update configuration extension handling by @Itxaka in #548
kairos-agent changes
- Version: v2.26.0 -> v2.27.0
- Improve messages for newcomers by @jimmykarily in #1108
- Fix TUI when terminal doesn't report size by @jimmykarily in #1109
- fix: Simplify grub file copying logic by @Itxaka in #1114
- feat: Expand extension management to include confext by @Itxaka in #1152
- fix: Correct confext directory path by @Itxaka in 2b0b20c
kairos-sdk changes
- No changes (v0.17.0)
kcrypt-discovery-challenger changes
- Version: v0.12.1 -> v0.12.2
- chore: bump Go version to 1.26.1 by @mauromorales in #189
provider-kairos changes
- Version: v2.14.0 -> v2.14.1
- bump go to 1.26.1 by @mauromorales in #879
edgevpn changes
- No changes (v0.31.1)
entities changes
- No changes (v0.8.3-0.20260109121712-af3b96567af9)
go-pluggable changes
- No changes (v0.0.0-20230126220627-7710299a0ae5)
yip changes
- Version: v1.21.2 -> v1.23.0
- feat: Implement package pinning support by @Itxaka in #253
- fix: detect #cloud-config after jinja/comment by @mvegter in #256
- feat: identify DNF as installer for Oracle Linux by @mvegter in #254
xpasswd changes
- No changes (v0.4.1)
v4.0.2-rc6
What's Changed
- rename factory action jobs for hadron by @mauromorales in #4008
- mark agx security scan as report only by @mauromorales in #4020
Full Changelog: v4.0.2-rc5...v4.0.2-rc6