Skip to content

Concourse

v8.2.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 10d Pipelines
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ci-cd concourse containers elm go pipelines
+1 more
runc

Affected surfaces

breaking_upgrade deps

ReleasePort's take

Moderate signal
editorial:auto 10d

The release bumps containerd to v2.3.1 to fix a privilege escalation CVE.

Why it matters: Patch containerd to versionβ€―v2.3.1 immediately to mitigate the reported privilege‑escalation vulnerability (CVE).

Summary

AI summary

Updates πŸ“¦ Bundled Resource Types, 🐞 Bug Fixes, and πŸ› οΈ Misc. Changes across a mixed release.

Changes in this release

Security Medium

Bump containerd to v2.3.1 to address a privilege escalation CVE.

Bump containerd to v2.3.1 to address a privilege escalation CVE.

Source: llm_adapter@2026-05-24

Confidence: low

β€”
Bugfix Medium

Fix CF connector issues reported by @IvanChalukov.

Fix CF connector issues reported by @IvanChalukov.

Source: llm_adapter@2026-05-24

Confidence: high

β€”
Bugfix Medium

Use session signing key to derive state signing key.

Use session signing key to derive state signing key.

Source: llm_adapter@2026-05-24

Confidence: high

β€”
Full changelog

What's Changed

🐞 Bug Fixes

  • Fix CF connector by @IvanChalukov in https://github.com/concourse/concourse/pull/9580
  • Use session signing key to derive state signing key by @taylorsilva in https://github.com/concourse/concourse/pull/9579

πŸ› οΈ Misc. Changes

  • Bump containerd to v2.3.1 to address a privilege escalation CVE in containerd by @taylorsilva in https://github.com/concourse/concourse/pull/9582

πŸ“¦ Bundled Resource Types

Full Changelog: https://github.com/concourse/concourse/compare/v8.2.1...v8.2.2

Security Fixes

  • containerd upgraded to v2.3.1 – addresses privilege escalation CVE (unspecified ID)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Concourse

Get notified when new releases ship.

Sign up free

About Concourse

Concourse is a container-based automation system written in Go. It's mostly used for CI/CD.

All releases β†’

Related context

Beta — feedback welcome: [email protected]