Skip to content

stable-20260706: LTS

Choose a tag to compare

@github-actions github-actions released this 06 Jul 19:27
5960400

Variants promoted

Variant Tag Digest
bluefin-lts :stable sha256:c2220ed08f07
bluefin-lts-nvidia :stable sha256:41823413956a

bluefin-lts and bluefin-lts-nvidia use the Fedora CoreOS stable kernel. The Kernel (LTS) version above applies to both.


Release card

Key components

Component Version Change
Kernel (LTS) 7.0.11-200
GNOME Shell 50.0-3.el10
Flatpak 1.18.0-1.el10
bootc 1.16.2-1.el10

77 updated, 8 added, 35 removed since the previous release. 1470 packages total.

Package changes

↑ 77 updated packages
Package From To
bpftool 7.7.0-2.el10 7.7.0-3.el10
centos-backgrounds 100.4-1.el10 100.5-1.el10
cifs-utils 7.5-2.el10 7.6-1.el10
cups 2.4.10-17.el10 2.4.10-18.el10
cups-client 2.4.10-17.el10 2.4.10-18.el10
cups-filesystem 2.4.10-17.el10 2.4.10-18.el10
cups-ipptool 2.4.10-17.el10 2.4.10-18.el10
cups-libs 2.4.10-17.el10 2.4.10-18.el10
ffmpeg 7.1.4-1.el10 7.1.5-1.el10
glibc 2.39-124.el10 2.39-126.el10
glibc-all-langpacks 2.39-124.el10 2.39-126.el10
glibc-common 2.39-124.el10 2.39-126.el10
glibc-devel 2.39-124.el10 2.39-126.el10
glibc-gconv-extra 2.39-124.el10 2.39-126.el10
glibc-minimal-langpack 2.39-124.el10 2.39-126.el10
highway 1.3.0-2.el10 1.3.0-1.el10_2
hyperv-daemons 0-0.50.20220731git.el10 0-0.51.20220731git.el10
hyperv-daemons-license 0-0.50.20220731git.el10 0-0.51.20220731git.el10
hypervkvpd 0-0.50.20220731git.el10 0-0.51.20220731git.el10
hypervvssd 0-0.50.20220731git.el10 0-0.51.20220731git.el10
intel-vsc-firmware 20260508-23.el10 20260624-24.el10
ipset 7.22-11.el10 7.22-12.el10
ipset-libs 7.22-11.el10 7.22-12.el10
iwlwifi-dvm-firmware 20260508-23.el10 20260624-24.el10
iwlwifi-mvm-firmware 20260508-23.el10 20260624-24.el10
just 1.51.0-1.el10_3 1.53.0-1.el10_3
kernel-headers 6.12.0-233.el10 6.12.0-243.el10
kernel-tools 6.12.0-233.el10 6.12.0-243.el10
kernel-tools-libs 6.12.0-233.el10 6.12.0-243.el10
libavcodec 7.1.4-1.el10 7.1.5-1.el10
libavdevice 7.1.4-1.el10 7.1.5-1.el10
libavfilter 7.1.4-1.el10 7.1.5-1.el10
libavformat 7.1.4-1.el10 7.1.5-1.el10
libavutil 7.1.4-1.el10 7.1.5-1.el10
libertas-firmware 20260508-23.el10 20260624-24.el10
libipa_hbac 2.13.0-1.el10 2.13.1-1.el10
libpostproc 7.1.4-1.el10 7.1.5-1.el10
libsss_certmap 2.13.0-1.el10 2.13.1-1.el10
libsss_idmap 2.13.0-1.el10 2.13.1-1.el10
libsss_nss_idmap 2.13.0-1.el10 2.13.1-1.el10
libsss_sudo 2.13.0-1.el10 2.13.1-1.el10
libswresample 7.1.4-1.el10 7.1.5-1.el10
libswscale 7.1.4-1.el10 7.1.5-1.el10
libxml2 2.12.5-12.el10 2.12.5-14.el10
mesa-dri-drivers 25.2.7-5.el10 26.1.1-1.el10
mesa-filesystem 25.2.7-5.el10 26.1.1-1.el10
mesa-libEGL 25.2.7-5.el10 26.1.1-1.el10
mesa-libGL 25.2.7-5.el10 26.1.1-1.el10
mesa-libgbm 25.2.7-5.el10 26.1.1-1.el10
mesa-vulkan-drivers 25.2.7-5.el10 26.1.1-1.el10
netronome-firmware 20260508-23.el10 20260624-24.el10
openexr-libs 3.1.10-11.el10 3.1.10-12.el10
openvpn 2.7.3-1.el10_3 2.7.5-1.el10_3
poppler 24.02.0-7.el10 24.02.0-10.el10
poppler-cpp 24.02.0-7.el10 24.02.0-10.el10
poppler-glib 24.02.0-7.el10 24.02.0-10.el10
poppler-utils 24.02.0-7.el10 24.02.0-10.el10
python3-libxml2 2.12.5-12.el10 2.12.5-14.el10
python3-perf 6.12.0-233.el10 6.12.0-243.el10
python3-virt-firmware 26.5.3-2.el10 26.6-1.el10
qemu-guest-agent 10.1.0-21.el10 10.1.0-23.el10
rsync 3.4.1-6.el10 3.4.4-1.el10
runc 1.4.0-1.el10_2 1.5.0-2.el10_3
sssd 2.13.0-1.el10 2.13.1-1.el10
sssd-ad 2.13.0-1.el10 2.13.1-1.el10
sssd-client 2.13.0-1.el10 2.13.1-1.el10
sssd-common 2.13.0-1.el10 2.13.1-1.el10
sssd-common-pac 2.13.0-1.el10 2.13.1-1.el10
sssd-ipa 2.13.0-1.el10 2.13.1-1.el10
sssd-kcm 2.13.0-1.el10 2.13.1-1.el10
sssd-krb5 2.13.0-1.el10 2.13.1-1.el10
sssd-krb5-common 2.13.0-1.el10 2.13.1-1.el10
sssd-ldap 2.13.0-1.el10 2.13.1-1.el10
sssd-nfs-idmap 2.13.0-1.el10 2.13.1-1.el10
sssd-proxy 2.13.0-1.el10 2.13.1-1.el10
uki-direct 26.5.3-2.el10 26.6-1.el10
virt-sb-certs 26.5.3-2.el10 26.6-1.el10
+ 8 added packages
Package Version
ghcr.io/projectbluefin/bluefin-lts stable
grub2-efi-aa64 2.12-49.el10
imath 3.1.10-4.el10
libasan 14.3.1-4.4.el10
libatomic 14.3.1-4.4.el10
libubsan 14.3.1-4.4.el10
opencsd 1.6.1-0.el10
shim-aa64 16.1-1.el10
− 35 removed packages
Package Last version
alsa-sof-firmware 2025.12.2-1.el10
cpuinfo 24.09.26-1.git1e83a2f.el10_1.1
fprintd 1.94.5-1.el10
fprintd-pam 1.94.5-1.el10
ghcr.io/projectbluefin/bluefin-lts-hwe stable
grub2-efi-x64 2.12-49.el10
grub2-pc 2.12-49.el10
grub2-pc-modules 2.12-49.el10
hypervfcopyd 0-0.50.20220731git.el10
intel-mediasdk 23.2.2-1.el10
intel-vpl-gpu-rt 26.1.6-1.el10_3
kmod-zfs 2.3.8-1
libfprint 1.94.9-3.el10
libnvpair3 2.3.8-1
libuutil3 2.3.8-1
libvmaf 3.0.0-2.el10_0
libvpl 2.16.0-1.el10_2
libzfs6 2.3.8-1
libzpool6 2.3.8-1
lm_sensors-libs 3.6.0-20.el10
mcelog 210-1.el10
microcode_ctl 20260210-1.el10
pcp-conf 7.1.5-2.el10
pcp-libs 7.1.5-2.el10
python3-pyzfs 2.3.8-1
python3.14 3.14.5-1.el10
python3.14-cffi 2.0.0-2.el10
python3.14-libs 3.14.5-1.el10
python3.14-pip-wheel 25.2-3.el10
python3.14-pycparser 2.22-4.el10
shim-x64 16.1-1.el10
svt-vp9-libs 0.3.0-13.el10_1
sysstat 12.7.6-4.el10
thermald 2.5.10-1.el10
zfs 2.3.8-1

Desktop Screenshot

Bluefin LTS desktop — stable-20260706

Captured from bluefin-lts:testing during automated e2e validation — testsuite

Supply chain verification

Supply chain

This image is signed, attested, and ships a full SPDX-JSON SBOM.
Every artifact below is verifiable without trusting this release page.

Tools required — install via Homebrew or see links in each section:

brew install cosign oras slsa-verifier

1 — Verify the image signature

cosign (Sigstore) verifies the keyless
OIDC signature created by GitHub Actions at build time.

cosign verify \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c2220ed08f072316550375095f511e92c62b1bbb4caf55d7ae24eae454463e6e

A valid response lists the certificate subject and OIDC issuer. Any tampered
image will produce a verification error.


2 — Fetch and inspect the SBOM

The SBOM (SPDX 2.3 JSON) is attached to the image as an
OCI referrer using
ORAS (CNCF graduated project).

# Discover the attached SBOM referrer
oras discover \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c2220ed08f072316550375095f511e92c62b1bbb4caf55d7ae24eae454463e6e

# Pull the SBOM to disk (replace SBOM_DIGEST with the digest from above)
oras pull \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@<SBOM_DIGEST>

The SBOM is also attached to this release as
bluefin-lts.spdx.json.


3 — Verify the SBOM attestation

The SBOM is also stored as a signed
GitHub SBOM attestation
in the Sigstore transparency log.

cosign verify-attestation \
  --type https://spdx.dev/Document \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c2220ed08f072316550375095f511e92c62b1bbb4caf55d7ae24eae454463e6e \
  | jq -r '.payload | @base64d | fromjson | .predicate.name'

4 — Verify SLSA Build L2 provenance

slsa-verifier (OpenSSF)
checks that this image was built by the expected workflow on the expected
source repository — not on a developer's laptop or a forked CI runner.

slsa-verifier verify-image \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c2220ed08f072316550375095f511e92c62b1bbb4caf55d7ae24eae454463e6e \
  --source-uri 'github.com/projectbluefin/bluefin-lts' \
  --source-versioned-tag 'stable-20260706'

You can also inspect the raw provenance:

cosign verify-attestation \
  --type slsaprovenance1 \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c2220ed08f072316550375095f511e92c62b1bbb4caf55d7ae24eae454463e6e \
  | jq -r '.payload | @base64d | fromjson | .predicate'

Full changelog and verification guide → https://docs.projectbluefin.io/changelogs

Full changelog → https://docs.projectbluefin.io/changelogs