Falco 0.34.1
Today we announce the release of Falco 0.34.1 🦅!
Novelties 🆕 and Fixes
Here's a minor update! This patch release addresses small but persistent issues that have been causing inconvenience for users:
- http_output not working as expected when the remote endpoint was using the HTTPS protocol;
- FALCO_ENGINE_VERSION was bumped since in Falco 0.34.0 new event fields were added for the process events;
- cleanups and fixes related to memory management were introduced in libs;
- avoid file descriptor leakage when checking for online CPUs in libpman.
Thanks to everyone in the community for helping us in spotting these annoying bugs 🐛! You make Falco successful 🦅!
Thanks as always to the Falco maintainers for their support and effort during the entire release process.
Try it! 🏎️
As usual, in case you just want to try out the stable Falco 0.34.1, you can install its packages following the process outlined in the docs:
Do you rather prefer using the container images? No problem at all! 🐳
You can read more about running Falco with Docker in the docs.
You can also find the Falcosecurity container images on the public AWS ECR gallery:
What's next 🔮
It's an exciting time for Falco as we see so many great improvements and features. What's more exciting is the fact that many great ideas and awesome work are going on to make the next big things happen.
The upcoming release will include complete syscall support in the modern BPF probe (feature parity with kernel module and current BPF probe) and introduce adaptive syscall selection for the Falco ruleset.
Let's meet 🤝
We meet every week in our community calls, if you want to know the latest and the greatest you should join us there!
If you have any questions
- Join the #falco channel on the Kubernetes Slack
- Join the Falco mailing list
Thanks to all the amazing contributors!
Cheers 🎊
Aldo