NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1101 by repository stars
Last release 19 days ago
18 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Some releases are documented
notes for 7 of 22 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
120 releases · first in 2023
One column per quarter.
…OpenVEX documents now include the required vulnerability name field for schema compliance.
Copacetic v0.15.0 expands support for minimal and application-centric workloads, led by Ubuntu Chiseled image patching and experimental Helm chart-aware patching. This release also adds SLES 16 support and includes substantial correctness, reproducibility, and performance improvements.
Copa can now patch both common Ubuntu Chiseled image layouts:
/var/lib/dpkg/status support targeted updates from scanner reports and comprehensive updates without a report. Copa applies updates through external Ubuntu tooling while preserving the full-status representation; the final image does not gain /var/lib/dpkg/status.d, apt, dpkg, BusyBox, or a shell./var/lib/chisel/manifest.wall support comprehensive re-cuts of their selected Chisel slices. Copa validates the manifest and resulting filesystem, preserves paths not owned by the original manifest and unaffected platform descriptors, rejects downgrades, and records the resolved Chisel release as OCI provenance.Native Chisel release selection can be inferred from /etc/os-release or overridden with --chisel-release. The CLI and bulk mode accept a named release, local release directory, or pinned HTTPS Git source; the BuildKit frontend accepts a named release or a supplied local build context and rejects Git URLs.
See the Ubuntu Chiseled image documentation and #1667.
The experimental chart mode renders a Helm chart with its default values, discovers images from supported Kubernetes workload locations, patches those images, and publishes a self-contained wrapper chart containing the patched image overrides. Patched images remain in their original repositories in single-chart mode; bulk PatchConfig supports a separate image target registry and explicit value-path overrides where automatic resolution is ambiguous.
Chart mode requires the Helm CLI, COPA_EXPERIMENTAL=1, --push, and credentials that can push both the patched images and wrapper chart.
See the bulk and Helm chart patching documentation and #1547.
Copa now supports SLES 16 BCI images and recognizes the SQLite RPM database used by SLES 16 alongside the existing NDB and Berkeley DB formats. Multi-platform fixtures and package-manager coverage were added for the new release.
See #1621.
Experimental Go patching is more reliable and reproducible:
go mod tidy -e allows CVE-relevant updates to proceed when an upstream project has unrelated module-graph problems. (#1602)github.com/docker/docker receive the required +incompatible suffix. (#1682)go.mod requirements, and rebuild steps are emitted deterministically. (#1680)VEX generation, VEX file output, tar hardlink rewriting, BuildKit progress forwarding, and terminal progress bookkeeping now use substantially fewer allocations and less CPU in large workloads. (#1639)
The release also updates BuildKit to 0.31.1 (#1675), containerd to 2.2.5 (#1631), Go to 1.25.13 (#1673), and gRPC to 1.83.1 (#1694), while expanding unit, integration, and end-to-end coverage across patching paths.
manifest.wall Chiseled images currently support comprehensive patching only; do not pass a vulnerability report. Trivy does not yet inventory packages from manifest.wall..deb archives and can add dependency packages or package-owned files that were not present in the original image. Maintainer scripts and dpkg triggers are disabled, lifecycle-package updates such as dpkg, apt, or bash are rejected, and the resulting filesystem and application should be validated before deployment.linux/arm/v6.See the installation guide. Release assets include Linux and macOS archives for amd64 and arm64, checksums, and SBOMs.
Thank you to @AruneshDwivedi, @SAY-5, @ashnamehrotra, @cwayne18, @jpinz, @omercnet, @robert-cronin, @sozercan, @y4ney, and everyone who tested, reviewed, documented, and reported issues for this release.
All changes since v0.14.0: v0.14.0...v0.15.0
The v0.14.1 and v0.14.2 patch fixes are also included in v0.15.0; see the v0.14.1 and v0.14.2 release notes.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…OpenVEX documents now include the required vulnerability name field for schema compliance.
⚠️ Pre-release. This release candidate has been superseded by Copacetic v0.15.0.
Copacetic v0.15.0-rc.0 previews expanded support for minimal and application-centric workloads, led by Ubuntu Chiseled image patching and experimental Helm chart-aware patching. This release candidate also adds SLES 16 support and includes substantial correctness, reproducibility, and performance improvements.
Copa can now patch both common Ubuntu Chiseled image layouts:
/var/lib/dpkg/status support targeted updates from scanner reports and comprehensive updates without a report. Copa applies updates through external Ubuntu tooling while preserving the full-status representation; the final image does not gain /var/lib/dpkg/status.d, apt, dpkg, BusyBox, or a shell./var/lib/chisel/manifest.wall support comprehensive re-cuts of their selected Chisel slices. Copa validates the manifest and resulting filesystem, preserves paths not owned by the original manifest and unaffected platform descriptors, rejects downgrades, and records the resolved Chisel release as OCI provenance.Native Chisel release selection can be inferred from /etc/os-release or overridden with --chisel-release. The CLI and bulk mode accept a named release, local release directory, or pinned HTTPS Git source; the BuildKit frontend accepts a named release or a supplied local build context and rejects Git URLs.
See the Ubuntu Chiseled image documentation and #1667.
The experimental chart mode renders a Helm chart with its default values, discovers images from supported Kubernetes workload locations, patches those images, and publishes a self-contained wrapper chart containing the patched image overrides. Patched images remain in their original repositories in single-chart mode; bulk PatchConfig supports a separate image target registry and explicit value-path overrides where automatic resolution is ambiguous.
Chart mode requires the Helm CLI, COPA_EXPERIMENTAL=1, --push, and credentials that can push both the patched images and wrapper chart.
See the bulk and Helm chart patching documentation and #1547.
Copa now supports SLES 16 BCI images and recognizes the SQLite RPM database used by SLES 16 alongside the existing NDB and Berkeley DB formats. Multi-platform fixtures and package-manager coverage were added for the new release.
See #1621.
Experimental Go patching is more reliable and reproducible:
go mod tidy -e allows CVE-relevant updates to proceed when an upstream project has unrelated module-graph problems. (#1602)github.com/docker/docker receive the required +incompatible suffix. (#1682)go.mod requirements, and rebuild steps are emitted deterministically. (#1680)VEX generation, VEX file output, tar hardlink rewriting, BuildKit progress forwarding, and terminal progress bookkeeping now use substantially fewer allocations and less CPU in large workloads. (#1639)
The release candidate also updates BuildKit to 0.31.1 (#1675), containerd to 2.2.5 (#1631), and Go to 1.25.13 (#1673), while expanding unit, integration, and end-to-end coverage across patching paths.
manifest.wall Chiseled images currently support comprehensive patching only; do not pass a vulnerability report. Trivy does not yet inventory packages from manifest.wall..deb archives and can add dependency packages or package-owned files that were not present in the original image. Maintainer scripts and dpkg triggers are disabled, lifecycle-package updates such as dpkg, apt, or bash are rejected, and the resulting filesystem and application should be validated before deployment.linux/arm/v6.See the installation guide. Release candidate assets include Linux and macOS archives for amd64 and arm64, checksums, and SBOMs.
Thank you to @AruneshDwivedi, @SAY-5, @ashnamehrotra, @cwayne18, @jpinz, @omercnet, @robert-cronin, @sozercan, @y4ney, and everyone who tested, reviewed, documented, and reported issues for this release candidate.
All changes since v0.14.0: v0.14.0...v0.15.0-rc.0
The v0.14.1 and v0.14.2 patch fixes are also included in v0.15.0-rc.0; see the v0.14.1 and v0.14.2 release notes.
875ab45 fix: avoid forced recompression on local export
This is a patch release on top of v0.14.0.
This is a patch release on top of v0.14.0.
/tmp on the published copacetic-frontend image. v0.14.0's FROM scratch rootfs caused every patch run via the BuildKit frontend to fail with stat /tmp: no such file or directory. Switched to gcr.io/distroless/static-debian12:nonroot plus a defense-in-depth ensureTempDir(). E2E now builds the real frontend.Dockerfile so this regression class cannot recur. (#1597)org.opencontainers.image.{source,revision,version,title}. Now captured pre-patch and forwarded to both single-platform and multi-platform export paths, with image.version rewritten consistently. (#1605)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Go binary patching — patch vulnerable Go binaries by rebuilding from source with updated stdlib/deps
PkgPath (#1485)ignore-errors=false (#1532)docker/docker to moby/moby/client (#1525)frontend.Dockerfile Go version aligned with go.mod and harden release pipeline (#1571)rebuildFailure replaces rebuildErrors []string in langmgr (#1560)Patch summary output showing total/patched/skipped vulnerabilities
⚠️ Pre-release.
frontend.Dockerfile Go version aligned with go.mod and harden release pipeline (#1571)Diff since rc.1: v0.14.0-rc.1...v0.14.0-rc.2
⚠️ Pre-release.
PkgPath (#1485)ignore-errors=false (#1532)docker/docker to moby/moby/client (#1525)rebuildFailure replaces rebuildErrors []string in langmgr (#1560)Full changelog: v0.13.0...v0.14.0-rc.1
Go binary patching — patch vulnerable Go binaries by rebuilding from source with updated stdlib/deps
⚠️ Pre-release.
PkgPath (#1485)ignore-errors=false (#1532)docker/docker to moby/moby/client (#1525)rebuildFailure replaces rebuildErrors []string in langmgr (#1560)Full changelog: v0.13.0...v0.14.0-rc.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
3c518cc fix: Node.js patching introduces new vulnerabilities through transitive dependencies
🧩 Experimental App-level Patching : Now supports Python and Node.js applications!
generate command to patch images. This provides support for any Docker CLI flags.--oci-dir flag to store patched artifacts locally when performing multi-platform patching.--exit-on-eol and --eol-api-url flags for customizable EOL validation.🧩 Experimental App-level Patching : Now supports Python and Node.js applications!
generate command to patch images. This provides support for any Docker CLI flags.--oci-dir flag to store patched artifacts locally when performing multi-platform patching.--exit-on-eol and --eol-api-url flags for customizable EOL validation.🧩 Experimental App-level Patching : Now supports Python and Node.js applications!
generate command to patch images. This provides support for any Docker CLI flags.--oci-dir flag to store patched artifacts locally when performing multi-platform patching.--exit-on-eol and --eol-api-url flags for customizable EOL validation.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
6e81904 chore: remove ignore errors for cbl mariner imgs and ignore CVE-2025-3576
generate command to patch images. This provides support for any Docker CLI flags.--oci-dir flag to store patched artifacts locally when performing multi-platform patching.--exit-on-eol and --eol-api-url flags for customizable EOL validation.Full Changelog: v0.11.1...v0.12.0-rc.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →