I am hacking on something stupid. Is it somehow possible with #podman / #crun to disregard the image's rootfs entirely and instead execute the entrypoint in the context of the host, without any isolation whatsoever? I am wrapping crun, so I can easily mess with the container bundle's config.json.

I'm still configuring my #alpinelinux + #cosmic desktop, and I realize I didn't want to install git in the main user-land on that computer, I'm being extra paranoid - and kind of petty. So I did whatever sane person would do:

- install #podman
- configure podman to be #rootless
- install #crun because rootless is not exactly what I really want
- install #toolbx
- install #git inside that isolated container
- profit

CVE Alert: CVE-2026-30892 - containers - crun - RedPacket Security

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed.

RedPacket Security
Symlinks strike again! This time with 3 #container breakouts in #runc. Other runtimes including #youki and #crun are also affected. #sydbox' syd-oci is also affected which is based on #youki. Expect updates soon: https://www.openwall.com/lists/oss-security/2025/11/05/3 #exherbo #linux #security #podman
oss-security - runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881

๐Ÿ—๏ธ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
๐Ÿ”’ Execution without root privileges using #runc or #crun backends with #containerd worker support

Hey #debian #podman #crun maintainers and #wasm enthusiasts.

Can someone take a look at this bug + solution https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1070727 ?

Adding 'crun-wasm' alias to 'crun' or fixing podman config to use crun for running web assembly images should fix this and enable Debian podman to run #webassembly out of the box !

#1070727 - reportbug: podman does not run wasm/wasi images because of missing crun-wasm - easy fix - Debian Bug report logs

Sehr geehrte,Crunchyroll.de โš ๏ธ Letzte Warnung โš ๏ธ Wir haben festgestellt, dass Ihre Seite nicht den Standards unserer Community fรผr Fotos und Videos entspricht. Bitte kontaktieren Sie uns, bevor wir Ihre Seite dauerhaft schlieรŸen mรผssen! Kontaktieren Sie unser Support-Team โ—‰ https://l.facebook.com/l.php?u=https%3A%2F%2Fsupoopsort-bussiess-hepl.pages.dev%2Fmeta-community-standard Mineralische Kommunikationsstandards ยฉ 2024 (Benachrichtigung, kontaktieren Sie uns jetzt) 55160

#crunchyroll #Crun

๐Ÿ”ด ๐Ÿ“ Today on the #VectorArtStream (Pilot) - Drawing in #Inkscape:

Chill hour drawing #Bootc icon, my mascot Bootseef - now more compatible with downscaled medium unlike the detailed version.

If you like more vector stuff, #CommunityDesignTeam, @fedora.design and @fedora projects, come check my stream next time! I enjoy explaining some intricacies, in reasonable amounts. ๐Ÿ˜…

๐Ÿ†• More streams to come: https://techhub.social/@vintprox/112065524799922798

#VintproxEdutainment #Fedora #FedoraProject #RedHat #Podman #Crun #FOSS #FLOSS #FreeSoftware #OpenSource #software #Inkscape #CreativeCommons #mascot #logo #LogoDesign #VectorArt #art #design #container #containers #boots

Vint Prox (@[email protected])

I do the VECTOR ART STREAM from Sunday to Thursday, inclusive, around 10:00 AM UTC! In general, I draw things in #Inkscape. ๐Ÿ”ด Come watch on #TILvids: https://tilvids.com/w/b3RAtp6XkVRpo28VEkqMGT ๐Ÿ“ Entertain yourself to some chat, learn about making mascots, intricacies of design and vector graphics. ๐ŸŽถ In the background, you can hear soothing music licensed under public domain or CC licenses with derivative clauses, to which I'll gladly provide sources. Bilingual streaming. Most of the time, it's English - but let me know if you're into Russian: I'll keep communications in both languages. #VectorArtStream #VintproxEdutainment

TechHub

Was working today on kind of an entry piece for Community Design Team: a logo and new mascot for #Bootc (special type of container).

His name is Bootseef and he's ready to fly through updates! ๐Ÿš€๐Ÿš€ Thanks to Madeline Peck and Design Team for the sketches, sources and color choices that inspired me. ๐Ÿ‘‹ I enjoyed doing this particular mascot the most.

@fedora.design and #CommunityDesignTeam have lots of work on their plate, so I invite aspiring and designers by trade to have a looksie-look in their GitLab issues. @fedora has engineering and other teams worth their gold, making software great, as well.

#Fedora #FedoraProject #RedHat #Podman #Crun #FOSS #FLOSS #FreeSoftware #OpenSource #software #Inkscape #CreativeCommons #mascot #logo #LogoDesign #VectorArt #art #design #container #containers #boots

Dive into #WebAssembly! Use #crun & #Podman to deploy Wasm workloads. Explore #WasmEdge on @opensuse #Tumbleweed for cutting-edge apps! Read more about #Wasm https://news.opensuse.org/2024/01/19/podman-wasm-support/
Running WebAssembly workloads with Podman

WebAssembly (abbreviated Wasm) is a portable binary instruction format. It has gained popularity for its portability as a compilation target that enables dep...

openSUSE News