stable-20260729: LTS
Variants promoted
| Variant | Tag | Digest |
|---|---|---|
bluefin-lts |
:stable |
sha256:5433eee15974 |
bluefin-lts-nvidia |
:stable |
sha256:baacaf0c451d |
bluefin-lts and bluefin-lts-nvidia use the Fedora CoreOS stable kernel. The Kernel (LTS) version above applies to both.
Key components
| Component | Version | Change |
|---|---|---|
| Kernel (LTS) | 7.0.12-201 |
|
| GNOME Shell | 50.0-3.el10 |
|
| Flatpak | 1.18.0-1.el10 |
|
| bootc | 1.16.2-1.el10 |
68 updated, 1 added since the previous release. 1495 packages total.
Package changes
↑ 68 updated packages
| Package | From | To |
|---|---|---|
aardvark-dns |
2.0.0-1.el10 |
2.0.0-2.el10 |
amd-gpu-firmware |
20260624-24.el10 |
20260722-25.el10 |
amd-ucode-firmware |
20260624-24.el10 |
20260722-25.el10 |
atheros-firmware |
20260624-24.el10 |
20260722-25.el10 |
brcmfmac-firmware |
20260624-24.el10 |
20260722-25.el10 |
c-ares |
1.34.6-1.el10 |
1.34.6-4.el10 |
cirrus-audio-firmware |
20260624-24.el10 |
20260722-25.el10 |
criu |
4.2-7.el10 |
4.2-8.el10 |
criu-libs |
4.2-7.el10 |
4.2-8.el10 |
dbus |
1.14.10-5.el10 |
1.14.10-6.el10 |
dbus-common |
1.14.10-5.el10 |
1.14.10-6.el10 |
dbus-daemon |
1.14.10-5.el10 |
1.14.10-6.el10 |
dbus-libs |
1.14.10-5.el10 |
1.14.10-6.el10 |
dbus-tools |
1.14.10-5.el10 |
1.14.10-6.el10 |
dnf-plugins-core |
4.7.0-10.el10 |
4.7.0-11.el10 |
glibc |
2.39-130.el10 |
2.39-131.el10 |
glibc-all-langpacks |
2.39-130.el10 |
2.39-131.el10 |
glibc-common |
2.39-130.el10 |
2.39-131.el10 |
glibc-devel |
2.39-130.el10 |
2.39-131.el10 |
glibc-gconv-extra |
2.39-130.el10 |
2.39-131.el10 |
glibc-minimal-langpack |
2.39-130.el10 |
2.39-131.el10 |
gobject-introspection |
1.79.1-6.el10 |
1.79.1-7.el10 |
grub2-common |
2.12-52.el10 |
2.12-53.el10 |
grub2-efi-x64 |
2.12-52.el10 |
2.12-53.el10 |
grub2-pc |
2.12-52.el10 |
2.12-53.el10 |
grub2-pc-modules |
2.12-52.el10 |
2.12-53.el10 |
grub2-tools |
2.12-52.el10 |
2.12-53.el10 |
grub2-tools-minimal |
2.12-52.el10 |
2.12-53.el10 |
grubby |
8.40-83.el10 |
8.40-84.el10 |
insights-core |
3.7.7-1.el10 |
3.7.8-1.el10 |
insights-core-selinux |
3.7.7-1.el10 |
3.7.8-1.el10 |
intel-audio-firmware |
20260624-24.el10 |
20260722-25.el10 |
intel-gpu-firmware |
20260624-24.el10 |
20260722-25.el10 |
intel-vsc-firmware |
20260624-24.el10 |
20260722-25.el10 |
iproute |
6.17.0-2.el10 |
7.0.0-2.el10 |
iproute-tc |
6.17.0-2.el10 |
7.0.0-2.el10 |
iwlwifi-dvm-firmware |
20260624-24.el10 |
20260722-25.el10 |
iwlwifi-mvm-firmware |
20260624-24.el10 |
20260722-25.el10 |
kernel-headers |
6.12.0-250.el10 |
6.12.0-251.el10 |
kernel-tools |
6.12.0-250.el10 |
6.12.0-251.el10 |
kernel-tools-libs |
6.12.0-250.el10 |
6.12.0-251.el10 |
libertas-firmware |
20260624-24.el10 |
20260722-25.el10 |
libnvme |
1.16.1-4.el10 |
1.16.2-1.el10 |
libxml2 |
2.12.5-14.el10 |
2.12.5-15.el10 |
libxslt |
1.1.39-9.el10 |
1.1.39-10.el10 |
linux-firmware |
20260624-24.el10 |
20260722-25.el10 |
linux-firmware-whence |
20260624-24.el10 |
20260722-25.el10 |
mt7xxx-firmware |
20260624-24.el10 |
20260722-25.el10 |
netavark |
2.0.0-1.el10 |
2.0.0-2.el10 |
netronome-firmware |
20260624-24.el10 |
20260722-25.el10 |
nvidia-gpu-firmware |
20260624-24.el10 |
20260722-25.el10 |
nxpwireless-firmware |
20260624-24.el10 |
20260722-25.el10 |
pam |
1.6.1-10.el10 |
1.6.1-11.el10 |
pam-libs |
1.6.1-10.el10 |
1.6.1-11.el10 |
podman |
6.0.1-1.el10 |
6.0.2-1.el10 |
python-unversioned-command |
3.12.13-2.el10 |
3.12.13-3.el10 |
python3 |
3.12.13-2.el10 |
3.12.13-3.el10 |
python3-dnf-plugin-versionlock |
4.7.0-10.el10 |
4.7.0-11.el10 |
python3-dnf-plugins-core |
4.7.0-10.el10 |
4.7.0-11.el10 |
python3-libs |
3.12.13-2.el10 |
3.12.13-3.el10 |
python3-libxml2 |
2.12.5-14.el10 |
2.12.5-15.el10 |
python3-perf |
6.12.0-250.el10 |
6.12.0-251.el10 |
realtek-firmware |
20260624-24.el10 |
20260722-25.el10 |
rest |
0.9.1-11.el10 |
0.9.1-12.el10 |
sos |
4.11.2-2.el10 |
4.11.2-3.el10 |
tailscale |
1.98.9-1 |
1.98.10-1 |
tiwilink-firmware |
20260624-24.el10 |
20260722-25.el10 |
tzdata |
2026b-1.el10 |
2026c-1.el10 |
+ 1 added packages
| Package | Version |
|---|---|
libcap-ng-python3 |
0.9.3-2.el10 |
Desktop Screenshot
Captured from bluefin-lts:testing during automated e2e validation — testsuite
Supply chain verification
Supply chain
This image is signed, attested, and ships a full SPDX-JSON SBOM.
Every artifact below is verifiable without trusting this release page.
Tools required — install via Homebrew or see links in each section:
brew install cosign oras slsa-verifier1 — Verify the image signature
cosign (Sigstore) verifies the keyless
OIDC signature created by GitHub Actions at build time.
cosign verify \
--certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5A valid response lists the certificate subject and OIDC issuer. Any tampered
image will produce a verification error.
2 — Fetch and inspect the SBOM
The SBOM (SPDX 2.3 JSON) is attached to the image as an
OCI referrer using
ORAS (CNCF graduated project).
# Discover the attached SBOM referrer
oras discover \
--artifact-type application/vnd.spdx+json \
ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5
# Pull the SBOM to disk (replace SBOM_DIGEST with the digest from above)
oras pull \
--artifact-type application/vnd.spdx+json \
ghcr.io/projectbluefin/bluefin-lts@<SBOM_DIGEST>The SBOM is also attached to this release as
bluefin-lts.spdx.json.
3 — Verify the SBOM attestation
The SBOM is also stored as a signed
GitHub SBOM attestation
in the Sigstore transparency log.
cosign verify-attestation \
--type https://spdx.dev/Document \
--certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
| jq -r '.payload | @base64d | fromjson | .predicate.name'4 — Verify SLSA Build L2 provenance
slsa-verifier (OpenSSF)
checks that this image was built by the expected workflow on the expected
source repository — not on a developer's laptop or a forked CI runner.
slsa-verifier verify-image \
ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
--source-uri 'github.com/projectbluefin/bluefin-lts' \
--source-versioned-tag 'stable-20260729'You can also inspect the raw provenance:
cosign verify-attestation \
--type slsaprovenance1 \
--certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions|execute-release)/\.github/workflows/' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
ghcr.io/projectbluefin/bluefin-lts@sha256:5433eee1597431bff47127edd53463f71385c2fb6888fecbe93d7fc6d144b6d5 \
| jq -r '.payload | @base64d | fromjson | .predicate'Full changelog and verification guide → https://docs.projectbluefin.io/changelogs
Full changelog → https://docs.projectbluefin.io/changelogs

