NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1903 by repository stars
Last release 6 months ago
15 Mar 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 14 of 14 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
912 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a fairly major update to umoci.
This is a fairly major update to umoci.
This update to umoci includes support for v1.1.1 of the OCI image
specification. For the most part, this mostly involves supporting reading new
features added to the specification (such as embedded-data descriptors and
subject references used by OCI artifact images), but at the moment umoci does
not yet support creating images utilising these features.
In addition, umoci also now supports generating config.json blobs that are
compliant with v1.2.1 of the OCI runtime specification. Note that we do not
explicitly use any of the newer features, this is mostly a quality-of-life
update to move away from our ancient pinned version of the runtime-spec.
github.com/opencontainers/umoci/oci/config/generate.Generator has had theConfigExposedPorts and ConfigVolumes methods now return a[]string instead of a map.(Set)OS and (Set)Architecture methods have been renamed to have aPlatform prefix (to match image-spec v1.1's organisational changes). They(Set)PlatformOS and (Set)PlatformArchitecture respectively.umoci stat now includes information about the manifest and configuration of
the image, both in the regular and JSON-formatted outputs.
umoci now has SOURCE_DATE_EPOCH support, to attempt to
make it easier to create reproducible images. Our behaviour is modelled after
tar --clamp-mtime, meaning that SOURCE_DATE_EPOCH will only be used to
modify the timestamps of files newer than SOURCE_DATE_EPOCH.
As umoci repack works based on diffs, this also means that only files that
were modified (and will thus be usually be included in the new layer) will
have their timestamps rewritten.
--history.created and umoci config --created will also now default to
SOURCE_DATE_EPOCH (if set).
With this change, umoci should be fairly compliant with reproducible builds.
Please let us know if you find any other problematic areas in umoci (we are
investigating some other possible causes of instability such as Go map
iteration).
In order to avoid the need for a patched gomtree package
that supports rootless mode, umoci now has a umoci raw mtree-validate
subcommand that implements the key gomtree validate features we need for
our integration tests.
Note that this subcommand is not intended for wider use outside of our tests
(and it is hidden from the help pages for a reason). Most users are probably
better off just using gomtree.
umoci --version now provides more information about the specification
versions supported by the umoci binary as well as the Go version used.
umoci config now supports specifying the architecture variant of the image
with --platform.variant. In addition, --os and --architecture can now
be set using --platform.os and --platform.arch respectively.
umoci new will not automatically fill the architecture variant on ARM
systems to match the host CPU.
umoci stat has had some minor changes made to howumoci stat would filter special characters inumoci repack will now truncate the mtime of files added to the layer tararchive/tar whichgomtree and so inconfig.json, umoci unpackThanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
umoci v0.6.0 -- "Please mind the gap between the train and the platform." Latest
Latest
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a fairly minor update to umoci, containing a few bugfixes for some potential issues, as well as finally removing the requirement for oci-image
This is a fairly minor update to umoci, containing a few bugfixes for
some potential issues, as well as finally removing the requirement for
oci-image-tool validation. We still do not support the latest image-spec
release, but decoupling for oci-image-tool is a very important first
step.
index.json, umoci will no longer incorrectly setmanifests entry to null (which was technically a violation of theWe now use go:embed to fill the version information of umoci --version,
allowing for users to get a reasonable binary with go install. However, we
still recommend using our official binaries, using distribution binaries, or
building from source with make.
Rather than using oci-image-tool validate for validating images in our
tests, we now make use of some hand-written smoke tests as well as the
jq-based validators maintained in docker-library/meta-scripts.
This is intended to act as a stop-gap until umoci validate is implemented
(and after that, we may choose to keep the jq-based validators as a
double-check that our own validators are working correctly).
Thanks to the following contributors who made this release possible:
This release is dedicated to our cat Yuki who sadly passed away on
Friday. Most of the code I've written in the past four years was written
with him purring away on my chest, and he was the most loving cat I've
ever met. Rest in peace, little buddy. I hope you enjoyed your time with
us, and I'll always keep you in my heart. 🖤
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
Nothing published for this version
Nothing published for this version
…media-type embedding and verification. CVE-2021-41190
This is a long-awaited release of umoci containing some Go API breaking
changes, some new features, and many other minor changes and
improvements.
Note that the Go API is still considered to be unstable, so downstream
users should generally be aware that future updates may contain more
breaking changes until we release umoci v1.0.0. However, the umoci CLI
is considered to be stable (as it has been widely used for nearly a
decade now) and we will endeavour to not make breaking changes.
This version of umoci requires Go 1.23 to build.
The method of configuring the on-disk format and MapOptions in
RepackOptions and UnpackOptions has been changed. The on-disk format is
now represented with the OnDiskFormat interface, with DirRootfs and
OverlayfsRootfs as possible options to use. MapOptions is now configured
inside the OnDiskFormat setting, which will require callers to adjust their
usage of the main umoci APIs. In particular, examples like
unpackOptions := &layer.UnpackOptions{
MapOptions: mapOptions,
WhiteoutMode: layer.StandardOCIWhiteout, // or layer.OverlayFSWhiteout
}
err := layer.UnpackManifest(ctx, engineExt, bundle, manifest, unpackOptions)will have to now be written as
unpackOptions := &layer.UnpackOptions{
OnDiskFormat: layer.DirRootfs{ // or layer.OverlayfsRootfs
MapOptions: mapOptions,
},
}
err := layer.UnpackManifest(ctx, engineExt, bundle, manifest, unpackOptions)and similarly
repackOptions := &layer.RepackOptions{
MapOptions: mapOptions,
TranslateOverlayWhiteouts: false, // or true
}
layerRdr, err := layer.GenerateLayer(path, deltas, repackOptions)will have to now be written as
repackOptions := &layer.RepackOptions{
OnDiskFormat: layer.DirRootfs{ // or layer.OverlayfsRootfs
MapOptions: mapOptions,
},
}
layerRdr, err := layer.GenerateLayer(path, deltas, repackOptions)Note that this means you can easily re-use the OnDiskFormat configuration
between both UnpackOptions and RepackOptions, removing the previous need
to translate between WhiteoutMode and TranslateOverlayWhiteouts.
For users of the API that need to extract the MapOptions from
UnpackOptions and RepackOptions, there is a new helper MapOptions which
will help extract it without doing interface type switching. For
OnDiskFormat there is also a Map method that gives you the inner
MapOptions regardless of type.
layer.NewTarExtractor now takes *UnpackOptions rather than
UnpackOptions to match the signatures of the other layer.* APIs. Passing
nil is equivalent to passing &UnpackOptions{}.
In umoci 0.4.7, we added support for overlayfs unpacking using the
still-unstable Go API. However, the implementation is still missing some key
features and so we will now return errors from APIs that are still missing
key features:
layer.UnpackManifest and layer.UnpackRootfs will now return an error
if UnpackOptions.OnDiskFormat is set to anything other than DirRootfs
(the default, equivalent to WhiteoutMode being set to
OCIStandardWhiteout in umoci 0.4.7).
This is because bundle-based unpacking currently tries to unpack all
layers into the same rootfs and generate an mtree manifest -- this
doesn't make sense for overlayfs-style unpacking and will produce garbage
bundles as a result. As such, we expect that nobody actually made use of
this feature (otherwise we would've seen bug reports complaining about it
being completely broken in the past 4 years). opencontainers/umoci#574
tracks re-enabling this feature (and exposing to umoci CLI users, if
possible).
Note that layer.UnpackLayer still supports OverlayfsRootfs
(OverlayFSWhiteout in umoci 0.4.7).
Already-extracted bundles with OverlayfsRootfs (OverlayFSWhiteout in
umoci 0.4.7) will now return an error when umoci operates on
them -- we included the whiteout mode in our umoci.json but as the
feature is broken, umoci will now refuse to operate on such bundles. Such
bundles could only have been created using the now-error-inducing
UnpackRootfs and UnpackManifest APIs mentioned above, and as mentioned
above we expect there to have been no real users of this feature.
Note that this only affects extracted bundles (a-la umoci unpack).
Images created from such bundles are unaffected (even though their
contents probably should be audited, since the implementation of this
feature was quite broken in this usecase).
Users should expect more breaking changes in the overlayfs-related Go APIs in
a future umoci 0.6 release, as there is still a lot of work left to do.
umoci unpack now supports handling layers compressed with zstd. This isumoci repack and umoci insert now support creating zstd-compressedauto) is to try to match the lastgzip if none of the layer--compress flag. You can also disable compression entirely using--compress=none but --compress=auto will never automatically choosenone compression.GenerateLayer and GenerateInsertLayer with OverlayfsRootfsTranslateOverlayWhiteouts in umoci 0.4.7) now supporttrusted.overlay.opaque=y and trusted.overlay.whiteoutOverlayfsRootfs now supports compatibility with the userxattr mountuser.overlay.* xattrs are used rather thantrusted.overlay.*). This is a pretty key compatibility featureUserXattr: true inOverlayfsRootfs. Note that (as with upstream overlayfs), only one xattrOverlayfsRootfs.UserXattr == true thentrusted.overlay.* xattrs will be treated like any other non-overlayfsmain.config.json version we generate is no1.0.0. We now use the version of the spec we have-dev suffix stripped, as such a prefix causes havoc withcgroup namespace to the default configuration generated by umoci unpack to make sure that our configuration plays nicely with runc when ongithub.com/pkg/errors to Go stdlib errorVerifiedReadCloser hardening work (to read all trailing bytes) which wouldEINTR on io.Copy operations. Newer Go versions have added moreEINTR errors in io paths that--uid-map and --gid-map rather than silently truncating the value.GenerateLayer (but not GenerateInsertLayer) withOverlayfsRootfs (called TranslateOverlayWhiteouts in umociUnpackLayer now correctly handles several aspects ofOverlayfsRootfs (OverlayFSWhiteout in umoci 0.4.7) extractiontrusted.overlay.opaque=y has very peculiar behaviour when a regularmknod c 0 0) is placed inside an opaque directory -- thereaddir but the file itself doesn't exist. ToUnpackLayer and Generate(Insert)Layer now correctly handletrusted.overlay.* xattr escaping when extracting and generating layers withtrusted.overlay.* xattrs, UnpackLayer willtrusted.overlay.overlay.*Generate(Insert)Layertrusted.overlay.overlay.* xattrs, they will be rewrittentrusted.overlay.* xattrs. If wetrusted.overlay.* xattr they will not be includedtrusted.overlay.origin might be automaticallyumoci unpack would previously return an error if aOverlayfsRootfs on-disk format. If there is a plainThanks to all of the following contributors for making this release
possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
umoci 0.5.0 -- "A wizard is never late, Frodo Baggins. Nor is he early; he arrives precisely when he means to."
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →