[TRACKING] Falco `0.45.0` release
Falco 0.45.0 Release
Will keep this issue updated with the current status and progress.
Date
Target release date: September 21st 2026
Release Steps
The process is described in this document.
External dependencies
- falcoctl
- driverkit
v0.23.2bump https://github.com/falcosecurity/falcoctl/pull/1067 -
google.golang.org/grpcbump https://github.com/falcosecurity/falcoctl/pull/1066 - drop the direct
github.com/docker/dockerdependency https://github.com/falcosecurity/falcoctl/pull/1065 - dismiss the 4
github.com/docker/dockeradvisories as not reachable (Sep 3, see the note below) - release
v0.14.0https://github.com/falcosecurity/falcoctl/releases/tag/v0.14.0 - bump
FALCOCTL_VERSIONin falco https://github.com/falcosecurity/falco/pull/3972 -
v0.14.1with the Dependabot bumps https://github.com/falcosecurity/falcoctl/releases/tag/v0.14.1 -
v0.14.2with the DKMS fix found in therc2package testing https://github.com/falcosecurity/falcoctl/releases/tag/v0.14.2 (Sep 14) - bump falcoctl to
0.14.2in falco https://github.com/falcosecurity/falco/pull/3996 - re-pin
0.14.1in falco https://github.com/falcosecurity/falco/pull/3985 (Sep 10)
- driverkit
- container plugin (see the note below)
- shipped in
0.7.2: systemd nerdctl cgroups fix,podman/v6+containerd v2.2.5migration,go-workerdependency bumps - CI unblocked (runner image regression) https://github.com/falcosecurity/plugins/issues/1510
-
mainbuild checked against Falco0.44.1(Sep 4) - pending PRs decided
- https://github.com/falcosecurity/plugins/pull/1501
- https://github.com/falcosecurity/plugins/pull/1502
- https://github.com/falcosecurity/plugins/pull/1020 excluded from
0.7.2, stale (Sep 4) - https://github.com/falcosecurity/plugins/pull/1486
- https://github.com/falcosecurity/plugins/pull/1506
- https://github.com/falcosecurity/plugins/pull/1488
- CI guard for the
libresolvlinkage https://github.com/falcosecurity/plugins/pull/1513 - dismiss the 8
github.com/docker/dockeradvisories as not reachable (Sep 4, see the note below) - fix the OCI publish step https://github.com/falcosecurity/plugins/pull/1514
- fix the build step (Debian bullseye EOL; base image decision after the release)
- release
0.7.2https://github.com/falcosecurity/plugins/releases/tag/plugins%2Fcontainer%2Fv0.7.2 (tarballs, OCI image, and signature verified, Sep 7) - pin
0.7.2in libs https://github.com/falcosecurity/libs/pull/3090 - pin
0.7.2in falco https://github.com/falcosecurity/falco/pull/3972 -
0.7.3with thegoogle.golang.org/grpcsecurity update https://github.com/falcosecurity/plugins/pull/1533 - engine bootstrap timeout and lookup retry fixes https://github.com/falcosecurity/plugins/pull/1534
- release
0.7.3https://github.com/falcosecurity/plugins/releases/tag/plugins%2Fcontainer%2Fv0.7.3 (tarballs, OCI artifact, and signature verified, Sep 10) -
0.7.4with thecontainerdsecurity update https://github.com/falcosecurity/plugins/pull/1536 - recover interrupted
containerdinspections at startup (the race found on Sep 10) https://github.com/falcosecurity/plugins/pull/1537 - release
0.7.4https://github.com/falcosecurity/plugins/releases/tag/plugins%2Fcontainer%2Fv0.7.4 (tarballs, OCI artifact, and signature verified, Sep 10) - pin
0.7.4in libs, onmasterand on the release branch - pin
0.7.4in falco https://github.com/falcosecurity/falco/pull/3985 (Sep 10)
- shipped in
- libs
-
0.26.0https://github.com/falcosecurity/libs/releases/tag/0.26.0 (fromrelease/0.26.xat8fc2f1fb, branched at45831918;rc1Sep 8,rc2Sep 10, final Sep 14)- https://github.com/falcosecurity/libs/releases/tag/0.26.0-rc1
- https://github.com/falcosecurity/libs/releases/tag/11.0.0-rc1%2Bdriver
- https://github.com/falcosecurity/libs/releases/tag/0.26.0-rc2
- https://github.com/falcosecurity/falco/pull/3971 (
rc1pin) - https://github.com/falcosecurity/falco/pull/3985 (
rc2pin) - https://github.com/falcosecurity/test-infra/pull/2061 (branch protection)
- https://github.com/falcosecurity/libs/pull/3097 (cherry-picks of the last fixes onto the release branch, Sep 9)
- https://github.com/falcosecurity/libs/pull/3103 (last cherry-picks onto the release branch, Sep 10)
- https://github.com/falcosecurity/libs/pull/3106 (kmod init fix and scap converter fix cherry-picked onto the release branch, Sep 11)
- https://github.com/falcosecurity/libs/pull/3110 (UTF-8 JSON fix cherry-picked onto the release branch, Sep 12)
- merged for
0.26.0(Sep 7-12)- https://github.com/falcosecurity/libs/pull/3108 (JSON output swallowed valid characters after malformed UTF-8, found on
rc2) - https://github.com/falcosecurity/libs/pull/3107 (scap converter fix for captures with unmatched enter events, low risk, tested in the final Falco round)
- https://github.com/falcosecurity/libs/pull/3104
- https://github.com/falcosecurity/libs/pull/3102
- https://github.com/falcosecurity/libs/pull/3100
- https://github.com/falcosecurity/libs/pull/3099
- https://github.com/falcosecurity/libs/pull/3085
- https://github.com/falcosecurity/libs/pull/3089
- https://github.com/falcosecurity/libs/pull/3098
- https://github.com/falcosecurity/libs/pull/3016
- https://github.com/falcosecurity/libs/pull/3021
- https://github.com/falcosecurity/libs/pull/3086
- https://github.com/falcosecurity/libs/pull/3088
- https://github.com/falcosecurity/libs/pull/3090
- https://github.com/falcosecurity/libs/pull/3091
- https://github.com/falcosecurity/libs/pull/3095
- https://github.com/falcosecurity/libs/pull/3096
- https://github.com/falcosecurity/libs/pull/3108 (JSON output swallowed valid characters after malformed UTF-8, found on
- moved to
0.27.0 - once the last PR is merged:
masterCI green (kernel matrix and nightlylatest mainline kerneljob included), Falco pinned to the candidate commit with CI green, then tagmasterCI green at45831918and kernel matrix green on11.0.0-rc1+driver(Sep 8); Falco CI green on the RC pin (Sep 8); nightly job green on45831918(Sep 9);release/0.26.xCI green atf3438e83(Sep 11);release/0.26.xCI green at8fc2f1fb, identical tomaster, nightly and kernel matrix green, tagged (Sep 14) - bump
CONTAINER_VERSIONhttps://github.com/falcosecurity/libs/pull/3090 - release descriptions the notes step is broken by the new GitHub token format, both set by hand (Sep 14); follow-up
-
- drivers
-
11.0.0+driverhttps://github.com/falcosecurity/libs/releases/tag/11.0.0%2Bdriver (Sep 14, see the note below) - fix the kmod build on Linux >= 7.3-rc1 before tagging (nightly arm64 job red since Aug 31, green again on Sep 8) https://github.com/falcosecurity/libs/pull/3091
- before generating the
11.0.0+driverconfigs, check both kernel-crawler lists are complete per distro (centosmissing on Sep 7, back on Sep 8;debianaarch64 incomplete on Sep 5 and Sep 8;photonx86_64 incomplete since the Broadcom move, fix merged on Sep 11, lists regenerate at the next daily crawler run;ubuntumissing on both arches on Sep 11, a slow mirror timed out and the crawler dropped the whole distro; both lists complete for every supported distro on Sep 14), and do not merge the DBG config PR while it drops kernels (both lists complete on Sep 17, configs generated the same day)- https://github.com/falcosecurity/kernel-crawler/issues/261 (the
ubuntudrop of Sep 11 is this mechanism) - https://github.com/falcosecurity/kernel-crawler/issues/260 (
debianmissing on x86_64 since February) - https://github.com/falcosecurity/kernel-crawler/pull/264 (
debianfix, merged Sep 14) - https://github.com/falcosecurity/kernel-crawler/issues/262 (
debianaarch64 partial on Sep 5 and Sep 8) - https://github.com/falcosecurity/kernel-crawler/pull/263 (
photonx86_64 fix) - https://github.com/falcosecurity/kernel-crawler/releases/tag/0.19.0 (ships both fixes, Sep 14)
- https://github.com/falcosecurity/test-infra/pull/2058
11.0.0+driverconfigs added,9.0.0,9.1.0,10.0.0and10.1.0dropped,10.2.0refreshed (Sep 17)
- https://github.com/falcosecurity/kernel-crawler/issues/261 (the
-
- driverkit
- k8s-metacollector
-
google.golang.org/grpcbump in the test server https://github.com/falcosecurity/k8s-metacollector/pull/226 - release
v0.1.4https://github.com/falcosecurity/k8s-metacollector/releases/tag/v0.1.4 (dependency and toolchain updates only; assets and images verified, Sep 9) - chart
0.3.2withappVersion0.1.4published (Sep 9)
-
- k8smeta plugin
- decide whether https://github.com/falcosecurity/plugins/pull/1489 goes in in, a new release is needed
- bump
PLUGIN_VERSIONto0.4.2https://github.com/falcosecurity/plugins/pull/1517 - release
plugins/k8smeta/v0.4.2https://github.com/falcosecurity/plugins/releases/tag/plugins%2Fk8smeta%2Fv0.4.2 (tarballs, OCI artifact, and signature verified, Sep 9) - bump
pluginReftok8smeta:0.4.2in the chart https://github.com/falcosecurity/falco/pull/3984 (Sep 10)
- rules
-
falco-rules-5.2.0https://github.com/falcosecurity/rules/releases/tag/falco-rules-5.2.0 (minor bump; tarball, OCI artifact, and signature verified) -
falco-sandbox-rules-6.2.0https://github.com/falcosecurity/rules/releases/tag/falco-sandbox-rules-6.2.0 (same round, verified) -
falco-incubating-rules-6.0.1unchanged, no release needed - pin
falco-rules-5.2.0in falco https://github.com/falcosecurity/falco/pull/3973 - open rules PRs deferred to after
0.45.0(Sep 4)
-
N.B. Driver tag (decision of Sep 4): 0.26.0 ships with 11.0.0+driver, since the auxmap fix bumps driver/API_VERSION to 11.0.0 (full DBG rebuild, SCAP_MINIMUM_DRIVER_API_VERSION moves to 11.0.0). driver/SCHEMA_VERSION is at 4.5.2 (Sep 7).
N.B. Falco overrides CONTAINER_VERSION in its own CMakeLists.txt, so both pins (libs and falco) have to be bumped.
N.B. The github.com/docker/docker advisories (GHSA-rg2x-37c3-w2rh, GHSA-x86f-5xw2-fm2r, GHSA-vp62-88p7-qqf5, GHSA-pxq6-2prw-chj9) have no patched version and are daemon-side only; falcoctl and the container plugin import the client side only, so they were dismissed as not reachable. Not blocking.
Manual Testing Action Items
- Running Falco on Kubernetes with the official Helm Charts (
rc3with chart9.2.0-rc1on k3s: install, upgrade, uninstall, collector and runtime restarts, Sep 15)- chart
9.2.0-rc1with0.45.0-rc2on test-infra https://github.com/falcosecurity/test-infra/pull/2065 (Sep 11)
- chart
- Running Falco on Kubernetes with the official operator (
rc3with operator0.4.1and chart0.3.1, Sep 15) - Running Falco from RPM and DEB artifacts
-
rc2: DEB on Debian 11 (glibc 2.31) and RPM on Rocky 8 (glibc 2.28), plugin init and rules dry run fine (Sep 11); same onrc3(Sep 15) - service startup, reboot and drivers (
rc3: DEB on Ubuntu 24.04 and RPM on Rocky 9, install, upgrade from0.44.1, reboots, kmod and modern eBPF, uninstall, Sep 15)
-
- Running Falco in a container with the official images (
rc2image, container guide and Docker quickstart, Sep 11;rc3image, Sep 15) - Running/fuzzing Falco with multiple event sources active in parallel (
rc2: syscalls,k8sauditandcontainerfor 20 minutes, no drops, Sep 11;rc3: 5 minutes, no drops, Sep 15) - Running/fuzzing Falco with variable syscall buffer dimension (
rc2: 1, 8 and 32 MiB buffers plus invalid presets, Sep 11; same onrc3, Sep 15) - Running Falco in all officially-supported architectures (x86_64, ARM64)
- x86_64 (
rc2, Sep 11;rc3, Sep 15) - ARM64
- x86_64 (
- Running Falco with the supported drivers (kmod, modern eBPF, scap files)
- modern eBPF and scap files (
rc2, Sep 11;rc3, Sep 15) - kmod (
rc3via DKMS on Ubuntu 24.04 and Rocky 9, Sep 15)
- modern eBPF and scap files (
- Test Falco with event generator (
rc2andrc3, event-generator0.13.0, Sep 11 and Sep 15) - Test that plugins are correctly loaded (
rc2:containerandk8saudit, from the image and the packages, Sep 11;rc3: same plusk8smetaon Kubernetes, Sep 15) - Test memory and CPU usage (with Valgrind and other tools)
- 20-minute run on
rc2: CPU and RSS stable, no drops (Sep 11); 5-minute run onrc3, stable (Sep 15) - Valgrind on
rc3: validation, replay and error paths, no leaks; one uninitialized field in the savefile FD reader, not blocking https://github.com/falcosecurity/libs/issues/3114 (Sep 16)
- 20-minute run on
- Test latest version of driver loader (falcoctl
0.14.2in therc3packages and thefalco-driver-loader:0.45.0-rc3image, Sep 15) - Test that
k8smetaplugin works as expected (0.4.2onrc3: pod fields, collector and runtime restarts, Sep 15) - Test that all Falco CLI options work as expected (
rc2, Sep 11;rc3, Sep 15) - Check that Falco log messages are correct and consistent
-
rc2andrc3: the unsupported-syscalls warning suggested the removed-Aflag text fixed onmasterandrelease/0.45.x(Sep 16) - the same warning fires when replaying a capture https://github.com/falcosecurity/falco/issues/4000 (moved into
0.45.0, fix in review onmasterandrelease/0.45.x, Sep 16)
-
- Test that Falco ruleset loading and validation works as expected (
rc2, Sep 11;rc3, Sep 15) - Test the new invalid UTF-8 sequence handling https://github.com/falcosecurity/falco/commit/65273dae
-
rc2: JSONoutput_fieldsswallowed valid characters after malformed bytes, fixed in libs https://github.com/falcosecurity/libs/pull/3108 (Sep 11) - re-test on
rc3: all therc2failures fixed (Sep 15)
-
Action Items
- Pre-Release
- Milestone
- Assign the missing milestone to merged PRs and closed issues since
0.44.0(Sep 3) - Check the release note block of every merged PR in the milestone (Sep 3; to be repeated for later merges)
- Assign the missing milestone to merged PRs and closed issues since
- Code freeze in falcosecurity/falco (Sep 11)
- Open release branch in Falco and protect it
release/0.45.xcreated atc0b24e3f(Sep 9); protection https://github.com/falcosecurity/test-infra/pull/2063 - See
External dependenciestask lists - Bump
FALCOSECURITY_LIBS_VERSION,DRIVER_VERSION,FALCOCTL_VERSION, andCONTAINER_VERSIONto the final tags- container plugin
0.7.4(Sep 10) - falcoctl
0.14.2onmasterandrelease/0.45.x(Sep 15) - rules https://github.com/falcosecurity/falco/pull/3973
- libs and driver
0.26.0and11.0.0+driveronmasterandrelease/0.45.x(Sep 14)
- container plugin
-
publish-dockerretries the crane download https://github.com/falcosecurity/falco/pull/3983 - cherry-pick everything merged on
mastersincerc1ontorelease/0.45.x, pins included https://github.com/falcosecurity/falco/pull/3986 (Sep 10)- https://github.com/falcosecurity/falco/pull/3993 (final pins, Sep 14)
- https://github.com/falcosecurity/falco/pull/3995 (packaging fix, chart constraints and falcoctl
0.14.2, Sep 15)
- Prebuilt drivers publish DBG builds ran on Sep 17: 4957 of 7830 buildable
11.0.0+driverconfigs published; 14 x86_64 Ubuntu cloud jobs never triggered (2036 configs), Debian >= 6.12 kmod fails in the builder image (pre-existing, postponed after the release), Photon and old Debian failures are environmental too (Sep 18) - Code thaw in falcosecurity/falco
- Changelog on the release branch
- Cherry-pick the changelog on master
- Milestone
- Release
- Github Release in the Falco repo
- bump the
rn2mdpin inrelease.yaml, the notes step fails with the new GitHub token format same fix as libs, onmasterandrelease/0.45.x(Sep 15) -
0.45.0-rc1https://github.com/falcosecurity/falco/releases/tag/0.45.0-rc1 (fromrelease/0.45.xatc0b24e3f; packages in the dev buckets and images tagged, Sep 9) -
0.45.0-rc2https://github.com/falcosecurity/falco/releases/tag/0.45.0-rc2 (fromrelease/0.45.xat00951ec5; libs0.26.0-rc2, falcoctl0.14.1, container plugin0.7.4; packages in the dev buckets and images tagged, Sep 11) -
0.45.0-rc3https://github.com/falcosecurity/falco/releases/tag/0.45.0-rc3 (tagged onmasteratbb0ca60c, same content asrelease/0.45.xataee018eeexcept the chart metadata; libs0.26.0, falcoctl0.14.2, container plugin0.7.4; packages in the dev buckets and images tagged, Sep 15) -
0.45.0-rc4https://github.com/falcosecurity/falco/releases/tag/0.45.0-rc4 (fromrelease/0.45.xat4692df0a, same content asmasterexcept the chart metadata; adds the SIGHUP reload fix and the Unix socket reload control; packages in the dev buckets and images tagged, Sep 18) -
0.45.0
- bump the
- Github Release in the Falco repo
- Website checklist https://github.com/falcosecurity/falco-website/issues/1587
- milestone collecting the
0.45website PRs https://github.com/falcosecurity/falco-website/milestone/10 - document the required glibc version for plugins (wide compatibility) https://github.com/falcosecurity/plugins/issues/70
- Create new snapshot for
v0.44 - Protect snapshot branch
- Bump
config/_default/versions/params.yaml - Merge the release blog post
- Merge all necessary documentation PRs
- drop the RHEL 8
LD_PRELOAD=/lib64/libresolv.so.2note, obsolete with container plugin0.7.2https://github.com/falcosecurity/falco-website/issues/1582
- drop the RHEL 8
- milestone collecting the
- Helm
- Release a new helm chart version
-
9.2.0-rc1for Falco0.45.0-rc2https://github.com/falcosecurity/falco/pull/3989 -
9.2.0-rc1published https://github.com/falcosecurity/charts/releases/tag/falco-9.2.0-rc1 -
9.2.0for Falco0.45.0
-
- Update
- Release a new helm chart version
Source: falcosecurity/falco