The release notes have been generated for the commit range v1.36.1…9c0e9a5 on Tue, 28 Jul 2026 17:56:03 UTC.
Download one of our static release bundles via our Google Cloud Bucket:
The OpenVEX report for this release is available at:
The SLSA provenance attestation for this release is available at:
All release artifacts (bundles, SBOMs, VEX, and provenance) are also available as signed OCI artifacts at ghcr.io/cri-o/bundle:9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.
To verify the artifact signatures via cosign, run:
> export COSIGN_EXPERIMENTAL=1
> cosign verify-blob cri-o.amd64.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.tar.gz \
--certificate-identity https://github.com/cri-o/packaging/.github/workflows/obs.yml@refs/heads/main \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/packaging \
--certificate-github-workflow-ref refs/heads/main \
--bundle cri-o.amd64.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.tar.gz.bundle
To verify the bill of materials (SBOM) in SPDX format using the bom tool, run:
> tar xfz cri-o.amd64.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.tar.gz
> bom validate -e cri-o.amd64.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.tar.gz.spdx -d cri-o
To verify the OpenVEX vulnerability report, run:
> cosign verify-blob cri-o.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.openvex.json \
--certificate-identity https://github.com/cri-o/packaging/.github/workflows/obs.yml@refs/heads/main \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/packaging \
--certificate-github-workflow-ref refs/heads/main \
--bundle cri-o.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.openvex.json.bundle
To verify the SLSA provenance attestation, run:
> cosign verify-blob cri-o.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.provenance.json \
--certificate-identity https://github.com/cri-o/packaging/.github/workflows/obs.yml@refs/heads/main \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-repository cri-o/packaging \
--certificate-github-workflow-ref refs/heads/main \
--bundle cri-o.9c0e9a5fcd33f139dcc47ef40bf4b0b8f1893616.provenance.json.bundle
namespace, pod, and container labels to CRI metrics (#10174, @openshift-cherrypick-robot)enable_cni_status_monitoring config option (default false) and
cni_status_grace_period (default 60s) to gate continuous CNI STATUS
monitoring and tolerate brief plugin disruptions during upgrades. (#10069, @openshift-cherrypick-robot)Nothing has changed.