What podman-container-tools/podman shipped
Written by FoxPlug from public releases; not affiliated with Podman. An automatic summary of the public release, pull request and commit data of github.com/podman-container-tools/podman. Podman did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- podman container inspect now exposes IsInitCtr and InitContainerType fields to distinguish init containers from regular containers. Pull request #29818
- PidsLimit 0 is now normalized to unlimited for runc to match Docker behavior across native CLI, compat API, and kube play. Pull request #29827
- The compat API now accepts inline seccomp profiles in HostConfig.SecurityOpt to support Docker clients that send profile JSON directly. Pull request #29726
- Auto-update now supports container filters through CLI, remote bindings, and REST API to selectively update container groups. Pull request #29791
- Rootless quadlet generation now correctly discovers drop-in directories for symlinked rootful quadlets. Pull request #29825
- The cgroup check was moved after help, completion, and subcommand checks to fix podman completion failures in sandboxed environments. Pull request #29832
- The ConsoleSize field in podman inspect now returns the actual TTY size for running containers with terminal enabled. Pull request #28579
- Exec can now be run with no attach streams requested to match Docker's detached exec behavior. Pull request #28686
- The compat API GET /images/{id}/json endpoint now omits the Created field when empty to match Docker API v1.44 behavior. Pull request #29761
- The compat distribution inspect endpoint has been implemented to fix a missing Docker API compatibility feature. Pull request #28358
Why it matters
This week brings several Docker compatibility fixes that improve interoperability with Docker clients and tooling. Init container inspection, seccomp profile handling, and PidsLimit normalization resolve real-world usage issues. Container filtering in auto-update enables more precise deployment workflows.
Changelog entry
- inspect: expose init container information with IsInitCtr and InitContainerType fields Pull request #29818
- compat: map pids-limit 0 to unlimited for runc consistency Pull request #29827
- compat API: accept inline seccomp profiles from Docker clients Pull request #29726
- auto-update: add container filters via CLI, remote bindings, and REST API Pull request #29791
- quadlet: resolve symlinks to find drop-ins in target unit directory Pull request #29825
- move cgroup check below help/completion/subcommands check for sandboxed environments Pull request #29832
- fix: return actual tty size in
container_inspectConsoleSize field Pull request #28579 - allow running exec with no attach streams requested for Docker compat Pull request #28686
- compat: omit empty Created field from GET /images/{id}/json Pull request #29761
- api: implement compat distribution inspect endpoint Pull request #28358
This week: init container inspection, Docker seccomp profile support, PidsLimit normalization, auto-update filters, quadlet symlink fixes, and more compat API improvements.
Podman shipped container inspection enhancements, improved Docker compatibility for seccomp profiles and exec operations, auto-update filtering for selective container updates, fixes for rootless quadlet symlinks, and standardized PidsLimit behavior. These changes strengthen Docker interoperability and support more sophisticated deployment scenarios.
Week of September 14, 2026
What shipped
- Podman 5.8.7 released with security fixes for CVE-2025-11395 addressing crafted layer tarballs in podman load and symlinks in podman volume import that could overwrite host files. Release
- Podman 6.1.2 released with security fixes for CVE-2025-11395 and related vulnerabilities. Release
- podman image scp now supports --compression-format and --compression-level options to compress archives during transfer, supporting gzip and zstd formats. Pull request #29395
- New libpod REST API endpoint for autoupdate functionality added, matching the capabilities of the CLI version. Pull request #27025
- Fixed compat container update to preserve existing restart policy unless explicitly overridden in the request. Pull request #29795
- Docker-compat network API now includes the IPRange field in IPAM config, mapping from Libpod's LeaseRange. Pull request #28633
- podman exec now forwards signals to the exec session's process group, preventing commands from continuing to run after exec is killed. Pull request #29525
- Health check command behavior fixed to use the health check command for startup health checks when --health-startup-cmd is not present, matching Docker behavior. Pull request #27857
- Documentation added explaining rootless bind-mount access through unmapped parent directories and user namespace ID mapping. Pull request #29375
- CPU real-time scheduler options --cpu-rt-period and --cpu-rt-runtime are now hidden and marked as no-ops since Podman 6 dropped cgroups v1 support. Pull request #29784
Why it matters
Two security releases address a critical vulnerability in image and volume import operations that could overwrite host files. Several improvements enhance container compatibility with Docker APIs and add new features for remote image transfer and API functionality.
Changelog entry
- Security: v5.8.7 released addressing CVE-2025-11395 for crafted layer tarballs and symlinks Release
- Security: v6.1.2 released addressing CVE-2025-11395 and related vulnerabilities Release
- Feature: podman image scp adds --compression-format and --compression-level options Pull request #29395
- Feature: New libpod REST API endpoint for autoupdate functionality Pull request #27025
- Fix: Compat container update preserves restart policy unless explicitly changed Pull request #29795
- Fix: Docker-compat network API includes IPRange field in IPAM config Pull request #28633
- Fix: podman exec now forwards signals to the exec session's process group Pull request #29525
- Fix: Health check command used for startup checks when --health-startup-cmd not set Pull request #27857
- Fix: Compat reports cgroup driver 'none' for rootless with cgroupfs Pull request #29303
- Change: --cpu-rt-period and --cpu-rt-runtime hidden and marked as no-ops Pull request #29784
Podman 5.8.7 and 6.1.2 released with security fixes for CVE-2025-11395. New features include compression for image scp, autoupdate REST API endpoint, and improved Docker API compatibility.
This week brings two security releases addressing CVE-2025-11395 affecting image and volume imports. New features include compression options for podman image scp transfers, an autoupdate endpoint in the libpod REST API, improved Docker API compatibility for networks and container updates, fixed signal forwarding in exec sessions, and better health check behavior matching Docker standards.