Portainer CE 2.43.0 Ships with Workflow Upgrades, Critical Security Fixes, and Dozens of Bug Resolutions

imagem 53

What’s New

Portainer CE 2.43.0 introduces a basic workflow details screen, giving you better visibility into your automation pipelines. The Environment Details view now shows GPU information, making it easier to track hardware resources. We’ve also made the setup token more prominent in installation logs to simplify initial configuration. Additionally, source, workflow, and artifact statuses are now tracked persistently, improving reliability.

Build Infrastructure Updates

The build pipeline has been upgraded to BuildKit 0.31.2, and image build provenance attestations now follow the SLSA v1.0 format. If your tooling parses these attestations, ensure compatibility with the new format. We’ve also bumped bbolt to 1.5.0 for better database performance.

Security Enhancements

This release addresses several important security issues. Unauthorized access via leftover service accounts has been fixed, and a path traversal vulnerability in the Swarm Compose deployer that could allow configs/secrets file paths to escape the project root has been closed. Multiple dependencies were updated to remediate known CVEs, including containerd, gRPC, axios, and shell-quote. We strongly recommend updating to stay protected.

Bug Fixes

We’ve squashed a long list of bugs across the entire platform. For Swarm users, stack deployments no longer hang indefinitely after a timeout, and image pull failures due to disk space are now properly reported. Private Docker Hub images in Swarm stacks should redeploy correctly with valid credentials. Edge stack issues, including re-assignments bringing back old state and tunnel resiliency over poor network links, have been improved.

On the Kubernetes side, RBAC policies now create the correct RoleBindings, and manifest deployments won’t silently fail when the “Use namespace from manifest” option is off. The Kubectl shell output now matches between Business and Community editions. We also fixed issues with Helm chart uninstall errors, application templates tooltips, and Ingress port display.

General UI fixes include resolving an infinite logout reload loop, fixing dark mode styling on the Workflows page, and preventing the containers table from breaking when many ports are exposed (now shows a “+N more” badge). GitOps users will be glad to see shared Git credentials returning for Sources, and the ListRefs performance on large repos has been addressed. Various other fixes improve stability for LDAP/AD settings, environment variables, and more.

Known Issues

On Async Edge environments, an invalid update schedule date may appear when browsing a snapshot. For Podman support, note that auto-onboarding scripts are not compatible, cross-socket additions between Podman and Docker servers are not possible, and only CentOS 9 with Podman 5 rootful is supported.

Leave a Comment

Your email address will not be published. Required fields are marked *