Falco 0.15.0 released.
Blog post from Sysdig
Falco 0.15.0 has been released, marking three years of the project's existence, and it includes significant enhancements such as bug fixes, updated rules, and a mitigation for CVE-2019-8339. This update also introduces support for CRI-O and containerd, aligning with their rising adoption as preferred container runtimes, thus benefiting users of IBM Kubernetes Service and OpenShift 4.0. The new release integrates MITRE ATT&CK Framework tags into Falco rules, providing better insight into detected tactics, techniques, and procedures. Performance improvements have been made, including asynchronous container metadata lookups and enhanced kernel ring buffer processing, with additional contributions expected from a Google Summer of Code student focused on Falco's performance. The CNCF-sponsored security audit further indicates the project's growth and maturity, and users are encouraged to update to the latest release via package repositories or Docker hub, with forthcoming updates to the Falco Helm chart for enhanced runtime support.