Files
codex/codex-rs/vendor/bubblewrap/release-checklist.md
Michael Bolin 123ec8b035 vendor: update bubblewrap to 0.11.2 (#21389)
## Why

`codex-rs/vendor/bubblewrap` had fallen behind upstream, and upstream
`v0.11.2` is the current Bubblewrap release. The release is a security
update for `CVE-2026-41163`, affecting setuid Bubblewrap builds, and
deprecates setuid support in favor of the default non-setuid build mode.

## What changed

- Refreshed the vendored Bubblewrap sources under
`codex-rs/vendor/bubblewrap` to upstream `v0.11.2`.
- Brought in the upstream `-Dsupport_setuid` build option, which
defaults setuid support off.
- Updated vendored release notes and documentation files included with
Bubblewrap.

## Verification

Not run locally; this PR only refreshes the vendored upstream Bubblewrap
source snapshot.

Upstream release:
https://github.com/containers/bubblewrap/releases/tag/v0.11.2
2026-05-06 18:10:30 +00:00

777 B

bubblewrap release checklist

  • Collect release notes in NEWS.md
  • Update version number in meson.build and release date in NEWS.md
  • Commit the changes
  • meson dist -C ${builddir}
  • Do any final smoke-testing, e.g. update a package, install and test it
  • git evtag sign v$VERSION
    • Include the release notes from NEWS.md in the tag message
  • git push --atomic origin main v$VERSION
  • https://github.com/containers/bubblewrap/releases/new
    • Fill in the new version's tag in the "Tag version" box
    • Title: $VERSION
    • Copy the release notes into the description
    • Upload the tarball that you built with meson dist
    • Get the sha256sum of the tarball and append it to the description
    • Publish release