Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 6, 2025

Bumps github.com/containerd/containerd/v2 from 2.1.3 to 2.1.5.

Release notes

Sourced from github.com/containerd/containerd/v2's releases.

containerd 2.1.5

Welcome to the v2.1.5 release of containerd!

The fifth patch release for containerd 2.1 contains various fixes and updates.

Security Updates

Highlights

Container Runtime Interface (CRI)

  • Disable event subscriber during task cleanup (#12410)
  • Add SystemdCgroup to default runtime options (#12253)
  • Fix userns with container image VOLUME mounts that need copy (#12242)

Image Distribution

  • Ensure errContentRangeIgnored error when range-get request is ignored (#12312)

Runtime

  • Update runc binary to v1.3.3 (#12478)

Deprecations

  • Postpone v2.2 deprecation items to v2.3 (#12431)

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors

  • Phil Estes
  • Akihiro Suda
  • Derek McGowan
  • Austin Vazquez
  • Rodrigo Campos
  • Maksym Pavlenko
  • Wei Fu
  • ningmingxiao
  • Akhil Mohan

... (truncated)

Commits
  • fcd4322 Merge pull request #12483 from austinvazquez/prep_2_1_5
  • fc5bdfe Prepare release notes for v2.1.5
  • c578c26 Update mailmap
  • 46a4a03 Merge commit from fork
  • 239ab87 Merge commit from fork
  • ac96e84 Merge pull request #12478 from k8s-infra-cherrypick-robot/cherry-pick-12475-t...
  • ed7edda Merge pull request #12470 from austinvazquez/2_1_bump_binaries_job_images
  • 3d713d3 runc: Update runc binary to v1.3.3
  • de4221c Update GHA runners to use latest images for basic binaries build
  • 559240f Merge pull request #12467 from austinvazquez/2_1_bump_go_1_24_9
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Nov 6, 2025
@dependabot dependabot bot requested review from a team as code owners November 6, 2025 15:14
@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 196.781734ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 106.863717ms

Standard Benchmark Metrics Skipped or Failed

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 373.967567ms
Throughput 267.40 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 39.888961727s
Average Latency 397.595553ms
Throughput 125.35 requests/second

NANOTDF Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 27.828956211s
Average Latency 277.686336ms
Throughput 179.67 requests/second

@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

@dependabot dependabot bot force-pushed the dependabot/go_modules/tests-bdd/github.com/containerd/containerd/v2-2.1.5 branch from 326ac53 to f1475fa Compare November 6, 2025 16:25
@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 159.12806ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 100.980341ms

Standard Benchmark Metrics Skipped or Failed

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 361.311412ms
Throughput 276.77 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 39.054666644s
Average Latency 388.958396ms
Throughput 128.03 requests/second

NANOTDF Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 27.341353936s
Average Latency 272.600776ms
Throughput 182.87 requests/second

@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

jakedoublev
jakedoublev previously approved these changes Nov 6, 2025
@jakedoublev jakedoublev added this pull request to the merge queue Nov 6, 2025
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Nov 6, 2025
@jakedoublev jakedoublev added this pull request to the merge queue Nov 6, 2025
@jakedoublev jakedoublev removed this pull request from the merge queue due to a manual request Nov 6, 2025
@jakedoublev
Copy link
Contributor

@dependabot rebase

Bumps [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) from 2.1.3 to 2.1.5.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v2.1.3...v2.1.5)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd/v2
  dependency-version: 2.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/go_modules/tests-bdd/github.com/containerd/containerd/v2-2.1.5 branch from f1475fa to 84ddb33 Compare November 6, 2025 23:05
@policy-bot-opentdf policy-bot-opentdf bot dismissed jakedoublev’s stale review November 6, 2025 23:05

Invalidated by push of 84ddb33

@jakedoublev jakedoublev enabled auto-merge November 6, 2025 23:05
@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 189.384492ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 101.696056ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 369.207952ms
Throughput 270.85 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 40.673398196s
Average Latency 405.206811ms
Throughput 122.93 requests/second

NANOTDF Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 28.3286233s
Average Latency 282.549525ms
Throughput 176.50 requests/second

@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

@github-actions
Copy link
Contributor

github-actions bot commented Nov 6, 2025

@jakedoublev jakedoublev added this pull request to the merge queue Nov 6, 2025
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Nov 6, 2025
@c-r33d c-r33d added this pull request to the merge queue Nov 7, 2025
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Nov 7, 2025
@jakedoublev jakedoublev added this pull request to the merge queue Nov 7, 2025
Merged via the queue into main with commit 003a0a0 Nov 7, 2025
58 of 64 checks passed
@jakedoublev jakedoublev deleted the dependabot/go_modules/tests-bdd/github.com/containerd/containerd/v2-2.1.5 branch November 7, 2025 01:35
@opentdf-automation
Copy link
Contributor

Created backport PR for release/service/v0.11:

Please cherry-pick the changes locally and resolve any conflicts.

git fetch origin backport-2885-to-release/service/v0.11
git worktree add --checkout .worktree/backport-2885-to-release/service/v0.11 backport-2885-to-release/service/v0.11
cd .worktree/backport-2885-to-release/service/v0.11
git reset --hard HEAD^
git cherry-pick -x 003a0a0d1b86f375592af00b2b3dfd4dcc1e185d
git push --force-with-lease

@jakedoublev
Copy link
Contributor

/backport

jakedoublev pushed a commit that referenced this pull request Nov 7, 2025
….1.5 in /tests-bdd (#2885)

Bumps
[github.com/containerd/containerd/v2](https://github.com/containerd/containerd)
from 2.1.3 to 2.1.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/containerd/containerd/releases">github.com/containerd/containerd/v2's
releases</a>.</em></p>
<blockquote>
<h2>containerd 2.1.5</h2>
<p>Welcome to the v2.1.5 release of containerd!</p>
<p>The fifth patch release for containerd 2.1 contains various fixes and
updates.</p>
<h3>Security Updates</h3>
<ul>
<li>
<p><strong>containerd</strong></p>
<ul>
<li><a
href="https://github.com/containerd/containerd/security/advisories/GHSA-pwhc-rpq9-4c8w"><strong>GHSA-pwhc-rpq9-4c8w</strong></a></li>
<li><a
href="https://github.com/containerd/containerd/security/advisories/GHSA-m6hq-p25p-ffr2"><strong>GHSA-m6hq-p25p-ffr2</strong></a></li>
</ul>
</li>
<li>
<p><strong>runc</strong></p>
<ul>
<li><a
href="https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r"><strong>GHSA-qw9x-cqr3-wc7r</strong></a></li>
<li><a
href="https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm"><strong>GHSA-cgrx-mc8f-2prm</strong></a></li>
<li><a
href="https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2"><strong>GHSA-9493-h29p-rfm2</strong></a></li>
</ul>
</li>
</ul>
<h3>Highlights</h3>
<h4>Container Runtime Interface (CRI)</h4>
<ul>
<li><strong>Disable event subscriber during task cleanup</strong> (<a
href="https://github.com/containerd/containerd/pull/12410">#12410</a>)</li>
<li><strong>Add SystemdCgroup to default runtime options</strong> (<a
href="https://github.com/containerd/containerd/pull/12253">#12253</a>)</li>
<li><strong>Fix userns with container image VOLUME mounts that need
copy</strong> (<a
href="https://github.com/containerd/containerd/pull/12242">#12242</a>)</li>
</ul>
<h4>Image Distribution</h4>
<ul>
<li><strong>Ensure errContentRangeIgnored error when range-get request
is ignored</strong> (<a
href="https://github.com/containerd/containerd/pull/12312">#12312</a>)</li>
</ul>
<h4>Runtime</h4>
<ul>
<li><strong>Update runc binary to v1.3.3</strong> (<a
href="https://github.com/containerd/containerd/pull/12478">#12478</a>)</li>
</ul>
<h4>Deprecations</h4>
<ul>
<li><strong>Postpone v2.2 deprecation items to v2.3</strong> (<a
href="https://github.com/containerd/containerd/pull/12431">#12431</a>)</li>
</ul>
<p>Please try out the release binaries and report any issues at
<a
href="https://github.com/containerd/containerd/issues">https://github.com/containerd/containerd/issues</a>.</p>
<h3>Contributors</h3>
<ul>
<li>Phil Estes</li>
<li>Akihiro Suda</li>
<li>Derek McGowan</li>
<li>Austin Vazquez</li>
<li>Rodrigo Campos</li>
<li>Maksym Pavlenko</li>
<li>Wei Fu</li>
<li>ningmingxiao</li>
<li>Akhil Mohan</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/containerd/containerd/commit/fcd43222d6b07379a4be9786bda52438f0dd16a1"><code>fcd4322</code></a>
Merge pull request <a
href="https://github.com/containerd/containerd/issues/12483">#12483</a>
from austinvazquez/prep_2_1_5</li>
<li><a
href="https://github.com/containerd/containerd/commit/fc5bdfeacefc7ff2a4f6bafaa2ed6453dbb8c472"><code>fc5bdfe</code></a>
Prepare release notes for v2.1.5</li>
<li><a
href="https://github.com/containerd/containerd/commit/c578c26bf9e9d3368e87edb837b706053c3ef30e"><code>c578c26</code></a>
Update mailmap</li>
<li><a
href="https://github.com/containerd/containerd/commit/46a4a03fb4131739e948f983af8c984eb0c36d61"><code>46a4a03</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/containerd/containerd/commit/239ab877db8edf31ffb2ae63d83919d1c242e8d2"><code>239ab87</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/containerd/containerd/commit/ac96e84217b88dd89608784aa673a3b14abd2c35"><code>ac96e84</code></a>
Merge pull request <a
href="https://github.com/containerd/containerd/issues/12478">#12478</a>
from k8s-infra-cherrypick-robot/cherry-pick-12475-t...</li>
<li><a
href="https://github.com/containerd/containerd/commit/ed7edda90c2c28aaa40a87cd2459d10db0a5d66c"><code>ed7edda</code></a>
Merge pull request <a
href="https://github.com/containerd/containerd/issues/12470">#12470</a>
from austinvazquez/2_1_bump_binaries_job_images</li>
<li><a
href="https://github.com/containerd/containerd/commit/3d713d3d0db35b9e0d587e482498c891cc6fa3f2"><code>3d713d3</code></a>
runc: Update runc binary to v1.3.3</li>
<li><a
href="https://github.com/containerd/containerd/commit/de4221cb7fb5f3ebb2fb5b2bdecfa907cdce94fb"><code>de4221c</code></a>
Update GHA runners to use latest images for basic binaries build</li>
<li><a
href="https://github.com/containerd/containerd/commit/559240f4179f377cc4a546bd4ad51b100b412ec9"><code>559240f</code></a>
Merge pull request <a
href="https://github.com/containerd/containerd/issues/12467">#12467</a>
from austinvazquez/2_1_bump_go_1_24_9</li>
<li>Additional commits viewable in <a
href="https://github.com/containerd/containerd/compare/v2.1.3...v2.1.5">compare
view</a></li>
</ul>
</details>
<br />

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/containerd/containerd/v2&package-manager=go_modules&previous-version=2.1.3&new-version=2.1.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/opentdf/platform/network/alerts).

</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit 003a0a0)
strantalis pushed a commit that referenced this pull request Nov 7, 2025
….1.5 in /tests-bdd [backport to release/service/v0.11] (#2889)

# Description
Backport of #2885 to `release/service/v0.11`.

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport release/service/v0.11 dependencies Pull requests that update a dependency file go Pull requests that update Go code size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants