Skip to content

stable-20260729: LTS

Choose a tag to compare

@github-actions github-actions released this 29 Jul 05:06
· 11 commits to main since this release
d9857f0

Variants promoted

Variant Tag Digest
bluefin-lts :stable sha256:5433eee15974
bluefin-lts-nvidia :stable sha256:baacaf0c451d

bluefin-lts and bluefin-lts-nvidia use the Fedora CoreOS stable kernel. The Kernel (LTS) version above applies to both.


Release card

Key components

Component Version Change
Kernel (LTS) 7.0.12-201
GNOME Shell 50.0-3.el10
Flatpak 1.18.0-1.el10
bootc 1.16.2-1.el10

68 updated, 1 added since the previous release. 1495 packages total.

Package changes

↑ 68 updated packages
Package From To
aardvark-dns 2.0.0-1.el10 2.0.0-2.el10
amd-gpu-firmware 20260624-24.el10 20260722-25.el10
amd-ucode-firmware 20260624-24.el10 20260722-25.el10
atheros-firmware 20260624-24.el10 20260722-25.el10
brcmfmac-firmware 20260624-24.el10 20260722-25.el10
c-ares 1.34.6-1.el10 1.34.6-4.el10
cirrus-audio-firmware 20260624-24.el10 20260722-25.el10
criu 4.2-7.el10 4.2-8.el10
criu-libs 4.2-7.el10 4.2-8.el10
dbus 1.14.10-5.el10 1.14.10-6.el10
dbus-common 1.14.10-5.el10 1.14.10-6.el10
dbus-daemon 1.14.10-5.el10 1.14.10-6.el10
dbus-libs 1.14.10-5.el10 1.14.10-6.el10
dbus-tools 1.14.10-5.el10 1.14.10-6.el10
dnf-plugins-core 4.7.0-10.el10 4.7.0-11.el10
glibc 2.39-130.el10 2.39-131.el10
glibc-all-langpacks 2.39-130.el10 2.39-131.el10
glibc-common 2.39-130.el10 2.39-131.el10
glibc-devel 2.39-130.el10 2.39-131.el10
glibc-gconv-extra 2.39-130.el10 2.39-131.el10
glibc-minimal-langpack 2.39-130.el10 2.39-131.el10
gobject-introspection 1.79.1-6.el10 1.79.1-7.el10
grub2-common 2.12-52.el10 2.12-53.el10
grub2-efi-x64 2.12-52.el10 2.12-53.el10
grub2-pc 2.12-52.el10 2.12-53.el10
grub2-pc-modules 2.12-52.el10 2.12-53.el10
grub2-tools 2.12-52.el10 2.12-53.el10
grub2-tools-minimal 2.12-52.el10 2.12-53.el10
grubby 8.40-83.el10 8.40-84.el10
insights-core 3.7.7-1.el10 3.7.8-1.el10
insights-core-selinux 3.7.7-1.el10 3.7.8-1.el10
intel-audio-firmware 20260624-24.el10 20260722-25.el10
intel-gpu-firmware 20260624-24.el10 20260722-25.el10
intel-vsc-firmware 20260624-24.el10 20260722-25.el10
iproute 6.17.0-2.el10 7.0.0-2.el10
iproute-tc 6.17.0-2.el10 7.0.0-2.el10
iwlwifi-dvm-firmware 20260624-24.el10 20260722-25.el10
iwlwifi-mvm-firmware 20260624-24.el10 20260722-25.el10
kernel-headers 6.12.0-250.el10 6.12.0-251.el10
kernel-tools 6.12.0-250.el10 6.12.0-251.el10
kernel-tools-libs 6.12.0-250.el10 6.12.0-251.el10
libertas-firmware 20260624-24.el10 20260722-25.el10
libnvme 1.16.1-4.el10 1.16.2-1.el10
libxml2 2.12.5-14.el10 2.12.5-15.el10
libxslt 1.1.39-9.el10 1.1.39-10.el10
linux-firmware 20260624-24.el10 20260722-25.el10
linux-firmware-whence 20260624-24.el10 20260722-25.el10
mt7xxx-firmware 20260624-24.el10 20260722-25.el10
netavark 2.0.0-1.el10 2.0.0-2.el10
netronome-firmware 20260624-24.el10 20260722-25.el10
nvidia-gpu-firmware 20260624-24.el10 20260722-25.el10
nxpwireless-firmware 20260624-24.el10 20260722-25.el10
pam 1.6.1-10.el10 1.6.1-11.el10
pam-libs 1.6.1-10.el10 1.6.1-11.el10
podman 6.0.1-1.el10 6.0.2-1.el10
python-unversioned-command 3.12.13-2.el10 3.12.13-3.el10
python3 3.12.13-2.el10 3.12.13-3.el10
python3-dnf-plugin-versionlock 4.7.0-10.el10 4.7.0-11.el10
python3-dnf-plugins-core 4.7.0-10.el10 4.7.0-11.el10
python3-libs 3.12.13-2.el10 3.12.13-3.el10
python3-libxml2 2.12.5-14.el10 2.12.5-15.el10
python3-perf 6.12.0-250.el10 6.12.0-251.el10
realtek-firmware 20260624-24.el10 20260722-25.el10
rest 0.9.1-11.el10 0.9.1-12.el10
sos 4.11.2-2.el10 4.11.2-3.el10
tailscale 1.98.9-1 1.98.10-1
tiwilink-firmware 20260624-24.el10 20260722-25.el10
tzdata 2026b-1.el10 2026c-1.el10
+ 1 added packages
Package Version
libcap-ng-python3 0.9.3-2.el10

Desktop Screenshot

Bluefin LTS desktop — stable-20260729

Captured from bluefin-lts:testing during automated e2e validation — testsuite

Supply chain verification

Supply chain

This image is signed, attested, and ships a full SPDX-JSON SBOM.
Every artifact below is verifiable without trusting this release page.

Tools required — install via Homebrew or see links in each section:

brew install cosign oras slsa-verifier

1 — Verify the image signature

cosign (Sigstore) verifies the keyless
OIDC signature created by GitHub Actions at build time.

cosign verify \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5

A valid response lists the certificate subject and OIDC issuer. Any tampered
image will produce a verification error.


2 — Fetch and inspect the SBOM

The SBOM (SPDX 2.3 JSON) is attached to the image as an
OCI referrer using
ORAS (CNCF graduated project).

# Discover the attached SBOM referrer
oras discover \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5

# Pull the SBOM to disk (replace SBOM_DIGEST with the digest from above)
oras pull \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@<SBOM_DIGEST>

The SBOM is also attached to this release as
bluefin-lts.spdx.json.


3 — Verify the SBOM attestation

The SBOM is also stored as a signed
GitHub SBOM attestation
in the Sigstore transparency log.

cosign verify-attestation \
  --type https://spdx.dev/Document \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
  | jq -r '.payload | @base64d | fromjson | .predicate.name'

4 — Verify SLSA Build L2 provenance

slsa-verifier (OpenSSF)
checks that this image was built by the expected workflow on the expected
source repository — not on a developer's laptop or a forked CI runner.

slsa-verifier verify-image \
  ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
  --source-uri 'github.com/projectbluefin/bluefin-lts' \
  --source-versioned-tag 'stable-20260729'

You can also inspect the raw provenance:

cosign verify-attestation \
  --type slsaprovenance1 \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
  | jq -r '.payload | @base64d | fromjson | .predicate'

Full changelog and verification guide → https://docs.projectbluefin.io/changelogs

Full changelog → https://docs.projectbluefin.io/changelogs