<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Falco – Reference</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/</link><description>Recent content in Reference on Falco</description><generator>Hugo -- gohugo.io</generator><language>en</language><atom:link href="https://v0-44--falcosecurity.netlify.app/docs/reference/feed.xml" rel="self" type="application/rss+xml"/><item><title>Docs: Glossary</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/glossary/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://v0-44--falcosecurity.netlify.app/docs/reference/glossary/</guid><description/></item><item><title>Docs: Falco Daemon</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/daemon/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://v0-44--falcosecurity.netlify.app/docs/reference/daemon/</guid><description/></item><item><title>Docs: Falco Rules</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/rules/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://v0-44--falcosecurity.netlify.app/docs/reference/rules/</guid><description/></item><item><title>Docs: Falco Plugins</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/plugins/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://v0-44--falcosecurity.netlify.app/docs/reference/plugins/</guid><description/></item><item><title>Docs: Changelog</title><link>https://v0-44--falcosecurity.netlify.app/docs/reference/changelog/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://v0-44--falcosecurity.netlify.app/docs/reference/changelog/</guid><description>
&lt;div class="changelog"&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.44.1" target="_blank"&gt;0.44.1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.25.4"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.25.4-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/10.2.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-10.2.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.44.1-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.44.1-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.44.1-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.44.1-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.44.1-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.44.1-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.44.1-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.44.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.44.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.44.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.44.1-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.44.1-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-44-1"&gt;v0.44.1&lt;/h2&gt;
&lt;p&gt;Released on 2026-06-11&lt;/p&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;feat(userspace/falco): add support for disabling BPF iterators [&lt;a href="https://github.com/falcosecurity/falco/pull/3879"&gt;#3879&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="bug-fixes"&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;fix: fix multiple issues related to BPF iterators (solved by bumping libs to &lt;code&gt;0.25.4&lt;/code&gt;) [&lt;a href="https://github.com/falcosecurity/falco/pull/3879"&gt;#3879&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-ekoops"&gt;Release Manager @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.44.1-rc1" target="_blank"&gt;0.44.1-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.44.0" target="_blank"&gt;0.44.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.25.2"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.25.2-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/10.2.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-10.2.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.44.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.44.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.44.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.44.0-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.44.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.44.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.44.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.44.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.44.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.44.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.44.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.44.0-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.44.0-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-44-0"&gt;v0.44.0&lt;/h2&gt;
&lt;p&gt;Released on 2026-05-26&lt;/p&gt;
&lt;h3 id="breaking-changes-warning"&gt;Breaking Changes :warning:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;new!: add backslash escaping support to &lt;code&gt;-o&lt;/code&gt; key-path parser for literal dots and brackets in YAML key names (e.g., -o 'my.dotted.key=val') [&lt;a href="https://github.com/falcosecurity/falco/pull/3835"&gt;#3835&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore!: drop gRPC output and server support [&lt;a href="https://github.com/falcosecurity/falco/pull/3798"&gt;#3798&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore!: drop gVisor engine support [&lt;a href="https://github.com/falcosecurity/falco/pull/3797"&gt;#3797&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore!: drop legacy BPF probe [&lt;a href="https://github.com/falcosecurity/falco/pull/3796"&gt;#3796&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;feat(engine): support string comparator modifiers (oneof/allof/anyof) [&lt;a href="https://github.com/falcosecurity/falco/pull/3878"&gt;#3878&lt;/a&gt;] - &lt;a href="https://github.com/therealbobo"&gt;@therealbobo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(config,rules): add &lt;code&gt;capture_events&lt;/code&gt; and &lt;code&gt;capture_filesize&lt;/code&gt; stop conditions for capture files [&lt;a href="https://github.com/falcosecurity/falco/pull/3824"&gt;#3824&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat: validation for unknown-key in rules [&lt;a href="https://github.com/falcosecurity/falco/pull/3805"&gt;#3805&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat(userspace/engine): add support for list transformer exception [&lt;a href="https://github.com/falcosecurity/falco/pull/3799"&gt;#3799&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore(build): Add USE_TSAN option to enable Thread Sanitizer. [&lt;a href="https://github.com/falcosecurity/falco/pull/3856"&gt;#3856&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: enable http_output, webserver, and metrics on macOS and Win [&lt;a href="https://github.com/falcosecurity/falco/pull/3827"&gt;#3827&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(docker): Restrict falco-webui service to local access only [&lt;a href="https://github.com/falcosecurity/falco/pull/3838"&gt;#3838&lt;/a&gt;] - &lt;a href="https://github.com/qux-bbb"&gt;@qux-bbb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: show condition text in warning snippet for folded scalar conditions [&lt;a href="https://github.com/falcosecurity/falco/pull/3858"&gt;#3858&lt;/a&gt;] - &lt;a href="https://github.com/ssam18"&gt;@ssam18&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: respect buffered_outputs YAML config value [&lt;a href="https://github.com/falcosecurity/falco/pull/3830"&gt;#3830&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): fix race condition in watchdog [&lt;a href="https://github.com/falcosecurity/falco/pull/3820"&gt;#3820&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(scripts): update RPM repository metadata before signing when re-signing all packages [&lt;a href="https://github.com/falcosecurity/falco/pull/3774"&gt;#3774&lt;/a&gt;] - &lt;a href="https://github.com/c2ndev"&gt;@c2ndev&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore(cmake): bump libs to &lt;code&gt;0.25.2&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3900"&gt;#3900&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: update falco rules to version &lt;code&gt;5.1.0&lt;/code&gt; and add &lt;code&gt;rules&lt;/code&gt; sub-command to &lt;code&gt;scripts/update-deps-version&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3890"&gt;#3890&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(chart): move Falco chart source to falco (1/5) [&lt;a href="https://github.com/falcosecurity/falco/pull/3889"&gt;#3889&lt;/a&gt;] - &lt;a href="https://github.com/c2ndev"&gt;@c2ndev&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(chart): move Falco chart source to falco [&lt;a href="https://github.com/falcosecurity/falco/pull/3884"&gt;#3884&lt;/a&gt;] - &lt;a href="https://github.com/c2ndev"&gt;@c2ndev&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs to &lt;code&gt;0.25.1&lt;/code&gt; and drivers to &lt;code&gt;10.2.0+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3888"&gt;#3888&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;upstream multiple http_output fixes for Win/macOS (from prempti) [&lt;a href="https://github.com/falcosecurity/falco/pull/3882"&gt;#3882&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: bump container plugin version to &lt;code&gt;0.7.1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3886"&gt;#3886&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): reference correct input name for sanitizers flag and update systemd-rpm-macros [&lt;a href="https://github.com/falcosecurity/falco/pull/3885"&gt;#3885&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(build): use Zig cross-compilation toolchain for external dependencies [&lt;a href="https://github.com/falcosecurity/falco/pull/3881"&gt;#3881&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake/modules): bump libs version to &lt;code&gt;0.25.0-rc2&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3876"&gt;#3876&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: bump container plugin version to &lt;code&gt;0.7.0&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3877"&gt;#3877&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ci(.github): replace &lt;code&gt;/area CI&lt;/code&gt; with &lt;code&gt;/area automation&lt;/code&gt; in PR template [&lt;a href="https://github.com/falcosecurity/falco/pull/3870"&gt;#3870&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest release candidates [&lt;a href="https://github.com/falcosecurity/falco/pull/3873"&gt;#3873&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3868"&gt;#3868&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump falcoctl dependency version to 0.13.0 [&lt;a href="https://github.com/falcosecurity/falco/pull/3869"&gt;#3869&lt;/a&gt;] - &lt;a href="https://github.com/c2ndev"&gt;@c2ndev&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/engine): replace invalid chars while JSON-encoding [&lt;a href="https://github.com/falcosecurity/falco/pull/3866"&gt;#3866&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3864"&gt;#3864&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build(docker): replace apt-key with keyring; use gnupg instead of gnupg2 [&lt;a href="https://github.com/falcosecurity/falco/pull/3844"&gt;#3844&lt;/a&gt;] - &lt;a href="https://github.com/parisnakitakejser"&gt;@parisnakitakejser&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump drivers to &lt;code&gt;10.0.0-rc2+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3863"&gt;#3863&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(scripts): add script updating libs/drivers cmake module versions [&lt;a href="https://github.com/falcosecurity/falco/pull/3862"&gt;#3862&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs/drivers to &lt;code&gt;0.24.0-rc1&lt;/code&gt;/&lt;code&gt;10.0.0-rc1+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3861"&gt;#3861&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ci(reusable_test_packages): produce core dumps when falco crashes [&lt;a href="https://github.com/falcosecurity/falco/pull/3859"&gt;#3859&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(config): prevent plugin library path traversal via relative paths [&lt;a href="https://github.com/falcosecurity/falco/pull/3850"&gt;#3850&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: multi thread safety issues [&lt;a href="https://github.com/falcosecurity/falco/pull/3852"&gt;#3852&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3823"&gt;#3823&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ci: restore minimum set of required permissions [&lt;a href="https://github.com/falcosecurity/falco/pull/3841"&gt;#3841&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sync: docs(CHANGELOG.md): 0.43.1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3854"&gt;#3854&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat(userspace/falco): add support for kernel iterator metrics [&lt;a href="https://github.com/falcosecurity/falco/pull/3840"&gt;#3840&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs: multi-thread falco high-level design proposal [&lt;a href="https://github.com/falcosecurity/falco/pull/3751"&gt;#3751&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(cmake): configure falco.yaml from current src dir [&lt;a href="https://github.com/falcosecurity/falco/pull/3821"&gt;#3821&lt;/a&gt;] - &lt;a href="https://github.com/therealbobo"&gt;@therealbobo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(metrics): Prevent race condition crash during metrics collection on shutdown [&lt;a href="https://github.com/falcosecurity/falco/pull/3741"&gt;#3741&lt;/a&gt;] - &lt;a href="https://github.com/adduali1310"&gt;@adduali1310&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3765"&gt;#3765&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(falco): fix warning in webserver.h [&lt;a href="https://github.com/falcosecurity/falco/pull/3816"&gt;#3816&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs: fix Contributing.md outdated references [&lt;a href="https://github.com/falcosecurity/falco/pull/3807"&gt;#3807&lt;/a&gt;] - &lt;a href="https://github.com/cluster2600"&gt;@cluster2600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(webserver): fix inconsistent include directives trying to compile the webserver on Apple [&lt;a href="https://github.com/falcosecurity/falco/pull/3802"&gt;#3802&lt;/a&gt;] - &lt;a href="https://github.com/legobrick"&gt;@legobrick&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(build): add support for gperftools CPU profiler [&lt;a href="https://github.com/falcosecurity/falco/pull/3771"&gt;#3771&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;revert: &amp;quot;chore(.github): put back temporary action for GPG key rotation&amp;quot; [&lt;a href="https://github.com/falcosecurity/falco/pull/3776"&gt;#3776&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(proposals): specify version enforcing the deprecation [&lt;a href="https://github.com/falcosecurity/falco/pull/3762"&gt;#3762&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(OWNERS): add irozzo-1A(Iacopo Rozzo) as reviewer [&lt;a href="https://github.com/falcosecurity/falco/pull/3773"&gt;#3773&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;39&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-ekoops"&gt;Release Manager @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.44.0-rc2" target="_blank"&gt;0.44.0-rc2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.44.0-rc1" target="_blank"&gt;0.44.0-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.43.1" target="_blank"&gt;0.43.1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.23.2"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.23.2-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/9.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-9.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.43.1-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.43.1-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.43.1-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.43.1-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.43.1-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.43.1-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.43.1-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.43.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.43.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.43.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.43.1-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.43.1-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-43-1"&gt;v0.43.1&lt;/h2&gt;
&lt;p&gt;Released on 2026-04-09&lt;/p&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;build: bump libs version to 0.23.2 and container plugin version to 0.6.4 [&lt;a href="https://github.com/falcosecurity/falco/pull/3851"&gt;#3851&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-leogr"&gt;Release Manager @leogr&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.43.0" target="_blank"&gt;0.43.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.23.1"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.23.1-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/9.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-9.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.43.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.43.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.43.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.43.0-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.43.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.43.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.43.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.43.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.43.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.43.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.43.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.43.0-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.43.0-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-43-0"&gt;v0.43.0&lt;/h2&gt;
&lt;p&gt;Released on 2026-01-28&lt;/p&gt;
&lt;h3 id="breaking-changes-warning"&gt;Breaking Changes :warning:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(userspace)!: show source config path only in debug builds [&lt;a href="https://github.com/falcosecurity/falco/pull/3787"&gt;#3787&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore: [NOTICE] The GPG key used to sign DEB/RPM packages has been rotated, and all existing packages have been re-signed. New key fingerprint: &lt;code&gt;478B2FBBC75F4237B731DA4365106822B35B1B1F&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3753"&gt;#3753&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(userspace): deprecate &lt;code&gt;--gvisor-generate-config&lt;/code&gt; CLI option [&lt;a href="https://github.com/falcosecurity/falco/pull/3784"&gt;#3784&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs: add deprecation notice for legacy eBPF in pkg install dialog [&lt;a href="https://github.com/falcosecurity/falco/pull/3786"&gt;#3786&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(scripts/falcoctl): increase follow interval to 1 week [&lt;a href="https://github.com/falcosecurity/falco/pull/3757"&gt;#3757&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs: add deprecation notice for legacy eBPF, gVisor and gRPC usage [&lt;a href="https://github.com/falcosecurity/falco/pull/3763"&gt;#3763&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(userspace): deprecate legacy eBPF probe, gVisor engine and gRPC [&lt;a href="https://github.com/falcosecurity/falco/pull/3763"&gt;#3763&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(engine): emit warning when the deprecated &lt;code&gt;evt.latency&lt;/code&gt; field family is used in a rule condition or output [&lt;a href="https://github.com/falcosecurity/falco/pull/3744"&gt;#3744&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix: prevent null pointer crash on &lt;code&gt;popen()&lt;/code&gt; failure in output_program [&lt;a href="https://github.com/falcosecurity/falco/pull/3722"&gt;#3722&lt;/a&gt;] - &lt;a href="https://github.com/vietcgi"&gt;@vietcgi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: correct falcoctl.yaml path in debian conffiles [&lt;a href="https://github.com/falcosecurity/falco/pull/3745"&gt;#3745&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;revert: chore(.github): temporary action for GPG key rotation [&lt;a href="https://github.com/falcosecurity/falco/pull/3766"&gt;#3766&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump falcoctl dependency version to &lt;code&gt;0.12.2&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3790"&gt;#3790&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump falcoctl dependency version to &lt;code&gt;0.12.1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3777"&gt;#3777&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump container plugin version to &lt;code&gt;0.6.1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3780"&gt;#3780&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/engine): missing closing quote in deprecated field warning [&lt;a href="https://github.com/falcosecurity/falco/pull/3779"&gt;#3779&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(.github): Put back gpg key rotation workflow [&lt;a href="https://github.com/falcosecurity/falco/pull/3772"&gt;#3772&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs/drivers to &lt;code&gt;0.23.1&lt;/code&gt;/&lt;code&gt;9.1.0+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3769"&gt;#3769&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump container plugin version to 0.6.0 [&lt;a href="https://github.com/falcosecurity/falco/pull/3768"&gt;#3768&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(proposals): add proposal for legacy probe, gVisor engine and gRPC output deprecation [&lt;a href="https://github.com/falcosecurity/falco/pull/3755"&gt;#3755&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs/drivers to &lt;code&gt;0.23.0&lt;/code&gt;/&lt;code&gt;9.1.0+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3760"&gt;#3760&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3754"&gt;#3754&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(metrics): Add null check for state.outputs in metrics collection [&lt;a href="https://github.com/falcosecurity/falco/pull/3740"&gt;#3740&lt;/a&gt;] - &lt;a href="https://github.com/adduali1310"&gt;@adduali1310&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs to &lt;code&gt;0.23.0-rc2&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3759"&gt;#3759&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake): bump libs/drivers to &lt;code&gt;0.23.0-rc1&lt;/code&gt;/&lt;code&gt;9.1.0-rc1+driver&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3758"&gt;#3758&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): revert changes to mitigate rate-limitar change [&lt;a href="https://github.com/falcosecurity/falco/pull/3752"&gt;#3752&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3723"&gt;#3723&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reduce image size [&lt;a href="https://github.com/falcosecurity/falco/pull/3746"&gt;#3746&lt;/a&gt;] - &lt;a href="https://github.com/jfcoz"&gt;@jfcoz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(RELEASE.md): specify target branch association upon release creation [&lt;a href="https://github.com/falcosecurity/falco/pull/3717"&gt;#3717&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(RELEASE.md): fix &lt;code&gt;rn2md&lt;/code&gt; cmd generating changelogs [&lt;a href="https://github.com/falcosecurity/falco/pull/3709"&gt;#3709&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(RELEASE.md): fix PRs filtering expr for checking release notes [&lt;a href="https://github.com/falcosecurity/falco/pull/3708"&gt;#3708&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(RELEASE.md): fix PRs filtering expression text [&lt;a href="https://github.com/falcosecurity/falco/pull/3707"&gt;#3707&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-ekoops"&gt;Release Manager @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.43.0-rc3" target="_blank"&gt;0.43.0-rc3&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.43.0-rc2" target="_blank"&gt;0.43.0-rc2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.43.0-rc1" target="_blank"&gt;0.43.0-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.1" target="_blank"&gt;0.42.1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.22.2"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.22.2-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/9.0.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-9.0.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.42.1-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.42.1-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.42.1-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.42.1-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.42.1-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.42.1-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.42.1-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.42.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.42.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.42.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.42.1-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.42.1-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-42-1"&gt;v0.42.1&lt;/h2&gt;
&lt;p&gt;Released on 2025-11-06&lt;/p&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;docs(CHANGELOG.md): update changelog for &lt;code&gt;0.42.0&lt;/code&gt; release [&lt;a href="https://github.com/falcosecurity/falco/pull/3730"&gt;#3730&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-leogr"&gt;Release Manager @leogr&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.0" target="_blank"&gt;0.42.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.22.1"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.22.1-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/9.0.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-9.0.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.42.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.42.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.42.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.42.0-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.42.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.42.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.42.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.42.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.42.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.42.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.42.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.42.0-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.42.0-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-42-0"&gt;v0.42.0&lt;/h2&gt;
&lt;p&gt;Released on 2025-10-22&lt;/p&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;feat: add &lt;code&gt;falco_libs.thread_table_auto_purging_interval_s&lt;/code&gt; and &lt;code&gt;thread_table_auto_purging_thread_timeout_s&lt;/code&gt; configuration options [&lt;a href="https://github.com/falcosecurity/falco/pull/3670"&gt;#3670&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat: log plugin version info at loading time [&lt;a href="https://github.com/falcosecurity/falco/pull/3657"&gt;#3657&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat: ability to add statically defined fields via &lt;code&gt;static_fields&lt;/code&gt; configuration [&lt;a href="https://github.com/falcosecurity/falco/pull/3557"&gt;#3557&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat(engine): emit warning when a rule containing the &lt;code&gt;evt.dir&lt;/code&gt; field in output is encountered [&lt;a href="https://github.com/falcosecurity/falco/pull/3697"&gt;#3697&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat(engine): emit warning when a rule containing a condition on the deprecated &lt;code&gt;evt.dir&lt;/code&gt; field is encountered [&lt;a href="https://github.com/falcosecurity/falco/pull/3690"&gt;#3690&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: ability to record &lt;code&gt;.scap&lt;/code&gt; files (capture feature) [&lt;a href="https://github.com/falcosecurity/falco/pull/3645"&gt;#3645&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(docker): includes sha on the image labels [&lt;a href="https://github.com/falcosecurity/falco/pull/3658"&gt;#3658&lt;/a&gt;] - &lt;a href="https://github.com/jcchavezs"&gt;@jcchavezs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(cmake,userspace,ci): add mimalloc support [&lt;a href="https://github.com/falcosecurity/falco/pull/3616"&gt;#3616&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;docs(falco.yaml): refactor config documentation [&lt;a href="https://github.com/falcosecurity/falco/pull/3685"&gt;#3685&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: fix &lt;code&gt;debian:buster&lt;/code&gt; apt debian repo URL in &lt;code&gt;:driver-loader-buster&lt;/code&gt; container image [&lt;a href="https://github.com/falcosecurity/falco/pull/3644"&gt;#3644&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: updagrade libs to version 0.22.1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3705"&gt;#3705&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: upgrade drivers to v9.0.0+driver [&lt;a href="https://github.com/falcosecurity/falco/pull/3701"&gt;#3701&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: upgrade cpp-httplib to v0.23.1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3647"&gt;#3647&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update: upgrade default ruleset to v5.0.0 [&lt;a href="https://github.com/falcosecurity/falco/pull/3700"&gt;#3700&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build: upgrade &lt;code&gt;falcoctl&lt;/code&gt; to v0.11.4 [&lt;a href="https://github.com/falcosecurity/falco/pull/3694"&gt;#3694&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(prometheus): deprecate enter events drop stats [&lt;a href="https://github.com/falcosecurity/falco/pull/3675"&gt;#3675&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(cmake): correct abseil-cpp for alpine build [&lt;a href="https://github.com/falcosecurity/falco/pull/3598"&gt;#3598&lt;/a&gt;] - &lt;a href="https://github.com/RomanenkoDenys"&gt;@RomanenkoDenys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: enable handling of multiple actions configured with &lt;code&gt;syscall_event_drops.actions&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3676"&gt;#3676&lt;/a&gt;] - &lt;a href="https://github.com/terror96"&gt;@terror96&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: disable dry-run restarts when Falco runs with config-watching disabled [&lt;a href="https://github.com/falcosecurity/falco/pull/3640"&gt;#3640&lt;/a&gt;] - &lt;a href="https://github.com/Proximyst"&gt;@Proximyst&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(userspace/falco): correct default duration calculation [&lt;a href="https://github.com/falcosecurity/falco/pull/3715"&gt;#3715&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(falcoctl): update falco rules to version 5 [&lt;a href="https://github.com/falcosecurity/falco/pull/3712"&gt;#3712&lt;/a&gt;] - &lt;a href="https://github.com/irozzo-1A"&gt;@irozzo-1A&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;doc(OWNERS): move incertum (Melissa Kilby) to emeritus_approvers [&lt;a href="https://github.com/falcosecurity/falco/pull/3605"&gt;#3605&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3689"&gt;#3689&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(docker): use new &lt;code&gt;ENV&lt;/code&gt; syntax in place of deprecated one [&lt;a href="https://github.com/falcosecurity/falco/pull/3696"&gt;#3696&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(cmake/modules): update rules to 5.0.0-rc1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3698"&gt;#3698&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/engine): fix logger date format [&lt;a href="https://github.com/falcosecurity/falco/pull/3672"&gt;#3672&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(OWNERS): add &lt;code&gt;ekoops&lt;/code&gt;(Leonardo Di Giovanna) as approver [&lt;a href="https://github.com/falcosecurity/falco/pull/3688"&gt;#3688&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3665"&gt;#3665&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Refactor: cppcheck cleanups [&lt;a href="https://github.com/falcosecurity/falco/pull/3649"&gt;#3649&lt;/a&gt;] - &lt;a href="https://github.com/sgaist"&gt;@sgaist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(userspace/engine): update falco engine version and checksum [&lt;a href="https://github.com/falcosecurity/falco/pull/3648"&gt;#3648&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3662"&gt;#3662&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3661"&gt;#3661&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3653"&gt;#3653&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): disable mimalloc for master builds. [&lt;a href="https://github.com/falcosecurity/falco/pull/3655"&gt;#3655&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;1208816&lt;/code&gt; to &lt;code&gt;be38001&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3651"&gt;#3651&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(falco.yaml): avoid out-of-sync config options for &lt;code&gt;container&lt;/code&gt; pl… [&lt;a href="https://github.com/falcosecurity/falco/pull/3650"&gt;#3650&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3636"&gt;#3636&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(CHANGELOG.md): release 0.41.3 (cherry-pick) [&lt;a href="https://github.com/falcosecurity/falco/pull/3634"&gt;#3634&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3628"&gt;#3628&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(CHANGELOG.md): release 0.41.2 (cherry-pick) [&lt;a href="https://github.com/falcosecurity/falco/pull/3623"&gt;#3623&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3618"&gt;#3618&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3602"&gt;#3602&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(falco.yaml): clean up plugins config leftover [&lt;a href="https://github.com/falcosecurity/falco/pull/3596"&gt;#3596&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;b4437c4&lt;/code&gt; to &lt;code&gt;4d51b18&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3607"&gt;#3607&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(docs): cherry pick CHANGELOG. [&lt;a href="https://github.com/falcosecurity/falco/pull/3600"&gt;#3600&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3592"&gt;#3592&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(docs): bumped changelog for release 0.41.0, master sync [&lt;a href="https://github.com/falcosecurity/falco/pull/3586"&gt;#3586&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;cb17833&lt;/code&gt; to &lt;code&gt;b4437c4&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3578"&gt;#3578&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;29&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;52&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-ekoops"&gt;Release Manager @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.0-rc4" target="_blank"&gt;0.42.0-rc4&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.0-rc3" target="_blank"&gt;0.42.0-rc3&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.0-rc2" target="_blank"&gt;0.42.0-rc2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.42.0-rc1" target="_blank"&gt;0.42.0-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.3" target="_blank"&gt;0.41.3&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.21.0"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.21.0-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/8.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-8.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.3-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.3-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.3-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.3-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.3-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.3-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.41.3-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.3-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.41.3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.3-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.3-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-41-3"&gt;v0.41.3&lt;/h2&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update: bump container plugin to v0.3.1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3629"&gt;#3629&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-leogr-ekoops"&gt;Release Manager @leogr @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.2" target="_blank"&gt;0.41.2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.21.0"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.21.0-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/8.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-8.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.2-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.2-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.2-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.2-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.2-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.2-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.41.2-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.2-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.41.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.2-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.2-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-41-2"&gt;v0.41.2&lt;/h2&gt;
&lt;p&gt;Released on 2025-06-17&lt;/p&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-leogr-ekoops"&gt;Release Manager @leogr @ekoops&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.1" target="_blank"&gt;0.41.1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.21.0"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.21.0-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/8.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-8.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.1-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.1-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.1-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.1-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.1-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.1-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.41.1-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.41.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.1-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.1-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-41-1"&gt;v0.41.1&lt;/h2&gt;
&lt;p&gt;Released on 2025-06-05&lt;/p&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(userspace/falco): when collecting metrics for stats_writer, create a &lt;code&gt;libs_metrics_collector&lt;/code&gt; for each source [&lt;a href="https://github.com/falcosecurity/falco/pull/3585"&gt;#3585&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): only enable prometheus metrics once all inspectors have been opened [&lt;a href="https://github.com/falcosecurity/falco/pull/3588"&gt;#3588&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.1-rc1" target="_blank"&gt;0.41.1-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.0" target="_blank"&gt;0.41.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.21.0"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.21.0-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/8.1.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-8.1.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.41.0-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.41.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.41.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.41.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.41.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.41.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.41.0-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.41.0-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-41-0"&gt;v0.41.0&lt;/h2&gt;
&lt;p&gt;Released on 2025-05-29&lt;/p&gt;
&lt;h3 id="breaking-changes-warning"&gt;Breaking Changes :warning:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cleanup(engine)!: only consider .yaml/.yml rule files [&lt;a href="https://github.com/falcosecurity/falco/pull/3551"&gt;#3551&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(userspace)!: deprecate print of &lt;code&gt;container.info&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3543"&gt;#3543&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(userspace/falco)!: drop deprecated in 0.40.0 CLI flags. [&lt;a href="https://github.com/falcosecurity/falco/pull/3496"&gt;#3496&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;new(falco): add json_include_output_fields option [&lt;a href="https://github.com/falcosecurity/falco/pull/3527"&gt;#3527&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(build,userspace): switch to use container plugin [&lt;a href="https://github.com/falcosecurity/falco/pull/3482"&gt;#3482&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(docker,scripts,ci): use an override config file to enable ISO 8601 output timeformat on docker images [&lt;a href="https://github.com/falcosecurity/falco/pull/3488"&gt;#3488&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore(build): update falcoctl to v0.11.2, rules for artifact follow to v4 [&lt;a href="https://github.com/falcosecurity/falco/pull/3580"&gt;#3580&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bumped falcoctl to 0.11.1 and rules to 4.0.0. [&lt;a href="https://github.com/falcosecurity/falco/pull/3577"&gt;#3577&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(containers): update opencontainers labels [&lt;a href="https://github.com/falcosecurity/falco/pull/3575"&gt;#3575&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(metrics): improve restart/hot_reload conditions inspection [&lt;a href="https://github.com/falcosecurity/falco/pull/3562"&gt;#3562&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update: empty &lt;code&gt;values&lt;/code&gt; in &lt;code&gt;exceptions&lt;/code&gt; won't emit a warning anymore [&lt;a href="https://github.com/falcosecurity/falco/pull/3529"&gt;#3529&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(falco.yaml): enable libs_logger by default with info level [&lt;a href="https://github.com/falcosecurity/falco/pull/3507"&gt;#3507&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(metrics/prometheus): gracefully handle multiple event sources, avoid erroneous duplicate metrics [&lt;a href="https://github.com/falcosecurity/falco/pull/3563"&gt;#3563&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): properly install rpm systemd-rpm-macro package on building packages pipeline [&lt;a href="https://github.com/falcosecurity/falco/pull/3521"&gt;#3521&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): init cmdline options after loading all config files [&lt;a href="https://github.com/falcosecurity/falco/pull/3493"&gt;#3493&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(cmake): add support for 16K kernel page to jemalloc [&lt;a href="https://github.com/falcosecurity/falco/pull/3490"&gt;#3490&lt;/a&gt;] - &lt;a href="https://github.com/Darkness4"&gt;@Darkness4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): fix jemalloc enabled in minimal build. [&lt;a href="https://github.com/falcosecurity/falco/pull/3478"&gt;#3478&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;4ccf111&lt;/code&gt; to &lt;code&gt;cb17833&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3572"&gt;#3572&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake/rules): bump to falco-rules-4.0.0-rc1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3567"&gt;#3567&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(userspace/falco): drop unused &lt;code&gt;libs_metrics_collector&lt;/code&gt; variable. [&lt;a href="https://github.com/falcosecurity/falco/pull/3566"&gt;#3566&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3564"&gt;#3564&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(build): fixed container custom_target &lt;code&gt;sed&lt;/code&gt; command. [&lt;a href="https://github.com/falcosecurity/falco/pull/3556"&gt;#3556&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;ae6ed41&lt;/code&gt; to &lt;code&gt;4ccf111&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3555"&gt;#3555&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(cmake): fix bundled c-ares cmake issue with e.g. SLES [&lt;a href="https://github.com/falcosecurity/falco/pull/3559"&gt;#3559&lt;/a&gt;] - &lt;a href="https://github.com/terror96"&gt;@terror96&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;1d2c6b1&lt;/code&gt; to &lt;code&gt;ae6ed41&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3553"&gt;#3553&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: revert &amp;quot;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;1d2c6b1&lt;/code&gt; to &lt;code&gt;371e431&lt;/code&gt;&amp;quot; [&lt;a href="https://github.com/falcosecurity/falco/pull/3552"&gt;#3552&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3550"&gt;#3550&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3549"&gt;#3549&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(adopters): added SafeDep as adopter [&lt;a href="https://github.com/falcosecurity/falco/pull/3548"&gt;#3548&lt;/a&gt;] - &lt;a href="https://github.com/KunalSin9h"&gt;@KunalSin9h&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3547"&gt;#3547&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3541"&gt;#3541&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace): fixed engine &lt;code&gt;openssl&lt;/code&gt; dep. [&lt;a href="https://github.com/falcosecurity/falco/pull/3535"&gt;#3535&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): fix outputs_http timeout [&lt;a href="https://github.com/falcosecurity/falco/pull/3523"&gt;#3523&lt;/a&gt;] - &lt;a href="https://github.com/benierc"&gt;@benierc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): use clang-19 to build modern_ebpf skeleton. [&lt;a href="https://github.com/falcosecurity/falco/pull/3537"&gt;#3537&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3531"&gt;#3531&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3530"&gt;#3530&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3525"&gt;#3525&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3520"&gt;#3520&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3516"&gt;#3516&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(README.md): cleanups and enhancements [&lt;a href="https://github.com/falcosecurity/falco/pull/3514"&gt;#3514&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3511"&gt;#3511&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;1d2c6b1&lt;/code&gt; to &lt;code&gt;371e431&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3510"&gt;#3510&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3508"&gt;#3508&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3506"&gt;#3506&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): when counting &lt;code&gt;-M&lt;/code&gt; timeout, do not account for async events [&lt;a href="https://github.com/falcosecurity/falco/pull/3505"&gt;#3505&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;d8415c1&lt;/code&gt; to &lt;code&gt;1d2c6b1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3504"&gt;#3504&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(proposals): correct typo in example [&lt;a href="https://github.com/falcosecurity/falco/pull/3499"&gt;#3499&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(docker): fixed entrypoints paths with new docker context. [&lt;a href="https://github.com/falcosecurity/falco/pull/3492"&gt;#3492&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;feat(falco/app): move actions not using config before &lt;code&gt;load_config&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3483"&gt;#3483&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;refactor(falco/app): apply early return pattern in actions code [&lt;a href="https://github.com/falcosecurity/falco/pull/3484"&gt;#3484&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;abf6637&lt;/code&gt; to &lt;code&gt;d8415c1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3489"&gt;#3489&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Add NETWAYS Web Services to ADOPTERS.md [&lt;a href="https://github.com/falcosecurity/falco/pull/3487"&gt;#3487&lt;/a&gt;] - &lt;a href="https://github.com/mocdaniel"&gt;@mocdaniel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: add back Falco static package to the release template. [&lt;a href="https://github.com/falcosecurity/falco/pull/3472"&gt;#3472&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;36&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.0-rc2" target="_blank"&gt;0.41.0-rc2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.41.0-rc1" target="_blank"&gt;0.41.0-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.40.0" target="_blank"&gt;0.40.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.20.0"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.20.0-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/8.0.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-8.0.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.40.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.40.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.40.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-static-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.40.0-static-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="tgz-static" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.40.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.40.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.40.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.40.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.40.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.40.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.40.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.40.0-buster&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.40.0-debian&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-40-0"&gt;v0.40.0&lt;/h2&gt;
&lt;p&gt;Released on 2025-01-28&lt;/p&gt;
&lt;h3 id="breaking-changes-warning"&gt;Breaking Changes :warning:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cleanup(userspac/falco)!: drop deprecated options. [&lt;a href="https://github.com/falcosecurity/falco/pull/3361"&gt;#3361&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;new(docker): streamline docker images [&lt;a href="https://github.com/falcosecurity/falco/pull/3273"&gt;#3273&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(build): reintroduce static build [&lt;a href="https://github.com/falcosecurity/falco/pull/3428"&gt;#3428&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(cmake,ci): added support for using jemalloc allocator instead of glibc one and use it by default for release artifacts [&lt;a href="https://github.com/falcosecurity/falco/pull/3406"&gt;#3406&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace,cmake): honor new plugins exposed suggested output formats [&lt;a href="https://github.com/falcosecurity/falco/pull/3388"&gt;#3388&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace/falco): allow entirely disabling plugin hostinfo support. [&lt;a href="https://github.com/falcosecurity/falco/pull/3412"&gt;#3412&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(ci): use &lt;code&gt;zig&lt;/code&gt; compiler instead of relying on centos7. [&lt;a href="https://github.com/falcosecurity/falco/pull/3307"&gt;#3307&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): add buffer_format_base64 option, deprecate -b [&lt;a href="https://github.com/falcosecurity/falco/pull/3358"&gt;#3358&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): add base_syscalls.all option to falco.yaml, deprecate -A [&lt;a href="https://github.com/falcosecurity/falco/pull/3352"&gt;#3352&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): add falco_libs.snaplen option, deprecate -S / --snaplen [&lt;a href="https://github.com/falcosecurity/falco/pull/3362"&gt;#3362&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update(cmake): bump falcoctl to v0.11.0 [&lt;a href="https://github.com/falcosecurity/falco/pull/3467"&gt;#3467&lt;/a&gt;] - &lt;a href="https://github.com/alacuku"&gt;@alacuku&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): add attestation for falco [&lt;a href="https://github.com/falcosecurity/falco/pull/3216"&gt;#3216&lt;/a&gt;] - &lt;a href="https://github.com/cpanato"&gt;@cpanato&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): build Falco in RelWithDebInfo, and upload Falco debug symbols as github artifacts [&lt;a href="https://github.com/falcosecurity/falco/pull/3452"&gt;#3452&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(build): DEB and RPM package requirements for dkms and kernel-devel are now suggestions [&lt;a href="https://github.com/falcosecurity/falco/pull/3450"&gt;#3450&lt;/a&gt;] - &lt;a href="https://github.com/jthiltges"&gt;@jthiltges&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(userspace/falco): fix container_engines.cri.sockets not loading from config file [&lt;a href="https://github.com/falcosecurity/falco/pull/3453"&gt;#3453&lt;/a&gt;] - &lt;a href="https://github.com/zayaanmoez"&gt;@zayaanmoez&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(docker): /usr/src/'*' no longer created if $HOST_PATH/usr/src didn't exist at startup [&lt;a href="https://github.com/falcosecurity/falco/pull/3434"&gt;#3434&lt;/a&gt;] - &lt;a href="https://github.com/shane-lawrence"&gt;@shane-lawrence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(docker): add brotli to the Falco image [&lt;a href="https://github.com/falcosecurity/falco/pull/3399"&gt;#3399&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/engine): explicitly disallow appending/modifying a rule with different sources [&lt;a href="https://github.com/falcosecurity/falco/pull/3383"&gt;#3383&lt;/a&gt;] - &lt;a href="https://github.com/mstemm"&gt;@mstemm&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;chore(falco.yaml): remove comments about cri cli arguments [&lt;a href="https://github.com/falcosecurity/falco/pull/3458"&gt;#3458&lt;/a&gt;] - &lt;a href="https://github.com/alacuku"&gt;@alacuku&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): fixed reusable_build/publish_docker workflows. [&lt;a href="https://github.com/falcosecurity/falco/pull/3459"&gt;#3459&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3455"&gt;#3455&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): bumped actions/upload-download-artifact. [&lt;a href="https://github.com/falcosecurity/falco/pull/3454"&gt;#3454&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(docker): drop unused libelf dep from container images [&lt;a href="https://github.com/falcosecurity/falco/pull/3451"&gt;#3451&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(docs): update &lt;code&gt;plugins_hostinfo&lt;/code&gt; config file comment. [&lt;a href="https://github.com/falcosecurity/falco/pull/3449"&gt;#3449&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(build): add RelWithDebInfo target [&lt;a href="https://github.com/falcosecurity/falco/pull/3440"&gt;#3440&lt;/a&gt;] - &lt;a href="https://github.com/shane-lawrence"&gt;@shane-lawrence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;283a62f&lt;/code&gt; to &lt;code&gt;abf6637&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3448"&gt;#3448&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(ci): use 4cpu-16gb arm runners [&lt;a href="https://github.com/falcosecurity/falco/pull/3447"&gt;#3447&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3439"&gt;#3439&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: avoid deprecated funcs to calculate sha256 [&lt;a href="https://github.com/falcosecurity/falco/pull/3442"&gt;#3442&lt;/a&gt;] - &lt;a href="https://github.com/federico-sysdig"&gt;@federico-sysdig&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): enable jemalloc in musl build. [&lt;a href="https://github.com/falcosecurity/falco/pull/3436"&gt;#3436&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;docs(falco.yaml): correct &lt;code&gt;buffered_outputs&lt;/code&gt; description [&lt;a href="https://github.com/falcosecurity/falco/pull/3427"&gt;#3427&lt;/a&gt;] - &lt;a href="https://github.com/leogr"&gt;@leogr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): use correct filtercheck_field_info. [&lt;a href="https://github.com/falcosecurity/falco/pull/3426"&gt;#3426&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3421"&gt;#3421&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: update the url for the docs about the concurrent queue classes [&lt;a href="https://github.com/falcosecurity/falco/pull/3415"&gt;#3415&lt;/a&gt;] - &lt;a href="https://github.com/Issif"&gt;@Issif&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(changelog): updated changelog for 0.39.2. [&lt;a href="https://github.com/falcosecurity/falco/pull/3410"&gt;#3410&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3392"&gt;#3392&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(cmake,docker): avoid cpp-httplib requiring brotli. [&lt;a href="https://github.com/falcosecurity/falco/pull/3400"&gt;#3400&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;407e997&lt;/code&gt; to &lt;code&gt;283a62f&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3391"&gt;#3391&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs to latest master. [&lt;a href="https://github.com/falcosecurity/falco/pull/3389"&gt;#3389&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): update libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3385"&gt;#3385&lt;/a&gt;] - &lt;a href="https://github.com/apps/github-actions"&gt;@github-actions[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Make enable()/disable() virtual so they can be overridden [&lt;a href="https://github.com/falcosecurity/falco/pull/3375"&gt;#3375&lt;/a&gt;] - &lt;a href="https://github.com/mstemm"&gt;@mstemm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): fixed shasum computation for bump-libs CI. [&lt;a href="https://github.com/falcosecurity/falco/pull/3379"&gt;#3379&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): use redhat advised method to check rpmsign success. [&lt;a href="https://github.com/falcosecurity/falco/pull/3376"&gt;#3376&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;e38fb3f&lt;/code&gt; to &lt;code&gt;407e997&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3374"&gt;#3374&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Compile output clone [&lt;a href="https://github.com/falcosecurity/falco/pull/3364"&gt;#3364&lt;/a&gt;] - &lt;a href="https://github.com/mstemm"&gt;@mstemm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): fixed bump-libs workflow syntax. [&lt;a href="https://github.com/falcosecurity/falco/pull/3369"&gt;#3369&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(ci): add a workflow to automatically bump libs on each monday. [&lt;a href="https://github.com/falcosecurity/falco/pull/3360"&gt;#3360&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;b6ad373&lt;/code&gt; to &lt;code&gt;e38fb3f&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3365"&gt;#3365&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(falco): reformat options::define [&lt;a href="https://github.com/falcosecurity/falco/pull/3356"&gt;#3356&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;49&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.40.0-rc1" target="_blank"&gt;0.40.0-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.39.2" target="_blank"&gt;0.39.2&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.18.2"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.18.2-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/7.3.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-7.3.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.2-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.2-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.39.2-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.2-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.2-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.39.2-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.2-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader-legacy:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-no-driver:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-distroless:0.39.2&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-39-2"&gt;v0.39.2&lt;/h2&gt;
&lt;p&gt;Released on 2024-11-21&lt;/p&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update(cmake): bumped falcoctl to v0.10.1. [&lt;a href="https://github.com/falcosecurity/falco/pull/3408"&gt;#3408&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump yaml-cpp to latest master. [&lt;a href="https://github.com/falcosecurity/falco/pull/3394"&gt;#3394&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update(ci): use arm64 CNCF runners for GH actions [&lt;a href="https://github.com/falcosecurity/falco/pull/3386"&gt;#3386&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.39.1" target="_blank"&gt;0.39.1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.18.1"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.18.1-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/7.3.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-7.3.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.1-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.1-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.39.1-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.1-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.1-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.39.1-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.1-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader-legacy:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-no-driver:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-distroless:0.39.1&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-39-1"&gt;v0.39.1&lt;/h2&gt;
&lt;p&gt;Released on 2024-10-09&lt;/p&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(engine): allow null init_config for plugin info [&lt;a href="https://github.com/falcosecurity/falco/pull/3372"&gt;#3372&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(engine): fix parsing issues in -o key={object} when the object definition contains a comma [&lt;a href="https://github.com/falcosecurity/falco/pull/3363"&gt;#3363&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): fix event set selection for plugin with parsing capability [&lt;a href="https://github.com/falcosecurity/falco/pull/3368"&gt;#3368&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update(changelog): updated changelog for 0.39.1. [&lt;a href="https://github.com/falcosecurity/falco/pull/3373"&gt;#3373&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.39.1-rc1" target="_blank"&gt;0.39.1-rc1&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.39.0" target="_blank"&gt;0.39.0&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/falcosecurity/libs/releases/tag/0.18.1"&gt;&lt;img src="https://img.shields.io/badge/LIBS-0.18.1-yellow" alt="LIBS" loading="lazy" /&gt;
&lt;/a&gt;
&lt;a href="https://github.com/falcosecurity/libs/releases/tag/7.3.0&amp;#43;driver"&gt;&lt;img src="https://img.shields.io/badge/DRIVER-7.3.0&amp;#43;driver-yellow" alt="DRIVER" loading="lazy" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packages&lt;/th&gt;
&lt;th&gt;Download&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;rpm-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.0-x86_64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.0-x86_64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-x86_64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/x86_64/falco-0.39.0-x86_64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rpm-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/rpm/falco-0.39.0-aarch64.rpm"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="rpm" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;deb-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/deb/stable/falco-0.39.0-aarch64.deb"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="deb" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tgz-aarch64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://download.falco.org/packages/bin/aarch64/falco-0.39.0-aarch64.tar.gz"&gt;&lt;img src="https://img.shields.io/badge/Falco-0.39.0-%2300aec7?style=flat-square" alt="tgz" loading="lazy" /&gt;
&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Images&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull public.ecr.aws/falcosecurity/falco:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-driver-loader-legacy:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-no-driver:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;docker pull docker.io/falcosecurity/falco-distroless:0.39.0&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="v0-39-0"&gt;v0.39.0&lt;/h2&gt;
&lt;p&gt;Released on 2024-10-01&lt;/p&gt;
&lt;h3 id="breaking-changes-warning"&gt;Breaking Changes :warning:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(falco_metrics)!: split tags label into multiple &lt;code&gt;tag_&lt;/code&gt;-prefixed labels [&lt;a href="https://github.com/falcosecurity/falco/pull/3337"&gt;#3337&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(falco_metrics)!: use full name for configs and rules files [&lt;a href="https://github.com/falcosecurity/falco/pull/3337"&gt;#3337&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(falco_metrics)!: rearrange &lt;code&gt;n_evts_cpu&lt;/code&gt; and &lt;code&gt;n_drops_cpu&lt;/code&gt; Prometheus metrics to follow best practices [&lt;a href="https://github.com/falcosecurity/falco/pull/3319"&gt;#3319&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(userspace/falco)!: drop deprecated -t,-T,-D options. [&lt;a href="https://github.com/falcosecurity/falco/pull/3311"&gt;#3311&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="major-changes"&gt;Major Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;feat(stats): add host_netinfo networking information stats family [&lt;a href="https://github.com/falcosecurity/falco/pull/3344"&gt;#3344&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): add json_include_message_property to have a message field without date and priority [&lt;a href="https://github.com/falcosecurity/falco/pull/3314"&gt;#3314&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace/falco,userspace/engine): rule json schema validation [&lt;a href="https://github.com/falcosecurity/falco/pull/3313"&gt;#3313&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): introduce append_output configuration [&lt;a href="https://github.com/falcosecurity/falco/pull/3308"&gt;#3308&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace/falco): added --config-schema action to print config schema [&lt;a href="https://github.com/falcosecurity/falco/pull/3312"&gt;#3312&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(falco): enable CLI options with -o key={object} [&lt;a href="https://github.com/falcosecurity/falco/pull/3310"&gt;#3310&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(config): add &lt;code&gt;container_engines&lt;/code&gt; config to falco.yaml [&lt;a href="https://github.com/falcosecurity/falco/pull/3266"&gt;#3266&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(metrics): add host_ifinfo metric [&lt;a href="https://github.com/falcosecurity/falco/pull/3253"&gt;#3253&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace,unit_tests): validate configs against schema [&lt;a href="https://github.com/falcosecurity/falco/pull/3302"&gt;#3302&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="minor-changes"&gt;Minor Changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;update(falco): upgrade libs to 0.18.1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3349"&gt;#3349&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(systemd): users can refer to systemd falco services with a constistent unique alias falco.service [&lt;a href="https://github.com/falcosecurity/falco/pull/3332"&gt;#3332&lt;/a&gt;] - &lt;a href="https://github.com/ekoops"&gt;@ekoops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs to 0.18.0 and driver to 7.3.0+driver. [&lt;a href="https://github.com/falcosecurity/falco/pull/3330"&gt;#3330&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(userspace/falco): deprecate &lt;code&gt;cri&lt;/code&gt; related CLI options. [&lt;a href="https://github.com/falcosecurity/falco/pull/3329"&gt;#3329&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bumped falcoctl to v0.10.0 and rules to 3.2.0 [&lt;a href="https://github.com/falcosecurity/falco/pull/3327"&gt;#3327&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(falco_metrics): change prometheus rules metric naming [&lt;a href="https://github.com/falcosecurity/falco/pull/3324"&gt;#3324&lt;/a&gt;] - &lt;a href="https://github.com/incertum"&gt;@incertum&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bug-fixes"&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;fix(falco): allow disable_cri_async from both CLI and config [&lt;a href="https://github.com/falcosecurity/falco/pull/3353"&gt;#3353&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(engine): sync outputs before printing stats at shutdown [&lt;a href="https://github.com/falcosecurity/falco/pull/3338"&gt;#3338&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(falco): allow plugin init_config map in json schema [&lt;a href="https://github.com/falcosecurity/falco/pull/3335"&gt;#3335&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/falco): properly account for plugin with CAP_PARSING when computing interesting sc set [&lt;a href="https://github.com/falcosecurity/falco/pull/3334"&gt;#3334&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="non-user-facing-changes"&gt;Non user-facing changes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;feat(cmake): add conditional builds for falcoctl and rules paths [&lt;a href="https://github.com/falcosecurity/falco/pull/3305"&gt;#3305&lt;/a&gt;] - &lt;a href="https://github.com/tembleking"&gt;@tembleking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(falco): ignore lint commit [&lt;a href="https://github.com/falcosecurity/falco/pull/3354"&gt;#3354&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(falco): apply code formatting [&lt;a href="https://github.com/falcosecurity/falco/pull/3350"&gt;#3350&lt;/a&gt;] - &lt;a href="https://github.com/poiana"&gt;@poiana&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: ignore_some_files for clang format [&lt;a href="https://github.com/falcosecurity/falco/pull/3351"&gt;#3351&lt;/a&gt;] - &lt;a href="https://github.com/Andreagit97"&gt;@Andreagit97&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sync: release 0.39.x [&lt;a href="https://github.com/falcosecurity/falco/pull/3340"&gt;#3340&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(userspace/engine): improve rule json schema to account for &lt;code&gt;source&lt;/code&gt; and &lt;code&gt;required_plugin_versions&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3328"&gt;#3328&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;cleanup(falco): use header file for json schema [&lt;a href="https://github.com/falcosecurity/falco/pull/3325"&gt;#3325&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(engine): modify append_output format [&lt;a href="https://github.com/falcosecurity/falco/pull/3322"&gt;#3322&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore: scaffolding for enabling code formatting [&lt;a href="https://github.com/falcosecurity/falco/pull/3321"&gt;#3321&lt;/a&gt;] - &lt;a href="https://github.com/Andreagit97"&gt;@Andreagit97&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs and driver to 0.18.0-rc1. [&lt;a href="https://github.com/falcosecurity/falco/pull/3320"&gt;#3320&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(ci): restore master and release CI workflow permissions. [&lt;a href="https://github.com/falcosecurity/falco/pull/3317"&gt;#3317&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fixed the token-permission and pinned-dependencies issue [&lt;a href="https://github.com/falcosecurity/falco/pull/3299"&gt;#3299&lt;/a&gt;] - &lt;a href="https://github.com/harshitasao"&gt;@harshitasao&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump falcoctl to v0.10.0-rc1 [&lt;a href="https://github.com/falcosecurity/falco/pull/3316"&gt;#3316&lt;/a&gt;] - &lt;a href="https://github.com/alacuku"&gt;@alacuku&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ci(insecure-api): update semgrep docker image [&lt;a href="https://github.com/falcosecurity/falco/pull/3315"&gt;#3315&lt;/a&gt;] - &lt;a href="https://github.com/francesco-furlan"&gt;@francesco-furlan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Add demo environment instructions and docker-config files [&lt;a href="https://github.com/falcosecurity/falco/pull/3295"&gt;#3295&lt;/a&gt;] - &lt;a href="https://github.com/bbl232"&gt;@bbl232&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;baecf18&lt;/code&gt; to &lt;code&gt;b6ad373&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3301"&gt;#3301&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs and driver to latest master [&lt;a href="https://github.com/falcosecurity/falco/pull/3283"&gt;#3283&lt;/a&gt;] - &lt;a href="https://github.com/jasondellaluce"&gt;@jasondellaluce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;342b20d&lt;/code&gt; to &lt;code&gt;baecf18&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3298"&gt;#3298&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;068f0f2&lt;/code&gt; to &lt;code&gt;342b20d&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3288"&gt;#3288&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;vote: add sgaist to OWNERS [&lt;a href="https://github.com/falcosecurity/falco/pull/3264"&gt;#3264&lt;/a&gt;] - &lt;a href="https://github.com/sgaist"&gt;@sgaist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Add Tulip Retail to adopters list [&lt;a href="https://github.com/falcosecurity/falco/pull/3291"&gt;#3291&lt;/a&gt;] - &lt;a href="https://github.com/bbl232"&gt;@bbl232&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;28b98b6&lt;/code&gt; to &lt;code&gt;068f0f2&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3282"&gt;#3282&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;c0a9bf1&lt;/code&gt; to &lt;code&gt;28b98b6&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3267"&gt;#3267&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Added the OpenSSF Scorecard Badge [&lt;a href="https://github.com/falcosecurity/falco/pull/3250"&gt;#3250&lt;/a&gt;] - &lt;a href="https://github.com/harshitasao"&gt;@harshitasao&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;ea57e78&lt;/code&gt; to &lt;code&gt;c0a9bf1&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3247"&gt;#3247&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake,userspace): bump libs and driver to latest master. [&lt;a href="https://github.com/falcosecurity/falco/pull/3263"&gt;#3263&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;If rule compilation fails, return immediately [&lt;a href="https://github.com/falcosecurity/falco/pull/3260"&gt;#3260&lt;/a&gt;] - &lt;a href="https://github.com/mstemm"&gt;@mstemm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new(userspace/engine): generalize indexable ruleset [&lt;a href="https://github.com/falcosecurity/falco/pull/3251"&gt;#3251&lt;/a&gt;] - &lt;a href="https://github.com/mstemm"&gt;@mstemm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs to master. [&lt;a href="https://github.com/falcosecurity/falco/pull/3249"&gt;#3249&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;df963b6&lt;/code&gt; to &lt;code&gt;ea57e78&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3240"&gt;#3240&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(ci): enable dummy tests on the testing framework. [&lt;a href="https://github.com/falcosecurity/falco/pull/3233"&gt;#3233&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;679a50a&lt;/code&gt; to &lt;code&gt;df963b6&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3231"&gt;#3231&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(cmake): bump libs and driver to master. [&lt;a href="https://github.com/falcosecurity/falco/pull/3225"&gt;#3225&lt;/a&gt;] - &lt;a href="https://github.com/FedeDP"&gt;@FedeDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chore(deps): Bump submodules/falcosecurity-rules from &lt;code&gt;9e56293&lt;/code&gt; to &lt;code&gt;679a50a&lt;/code&gt; [&lt;a href="https://github.com/falcosecurity/falco/pull/3222"&gt;#3222&lt;/a&gt;] - &lt;a href="https://github.com/apps/dependabot"&gt;@dependabot[bot]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;update(docs): update CHANGELOG for 0.38.0 (master branch) [&lt;a href="https://github.com/falcosecurity/falco/pull/3224"&gt;#3224&lt;/a&gt;] - &lt;a href="https://github.com/LucaGuerra"&gt;@LucaGuerra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="statistics"&gt;Statistics&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;MERGED PRS&lt;/th&gt;
&lt;th&gt;NUMBER&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Not user-facing&lt;/td&gt;
&lt;td&gt;35&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Release note&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4 id="release-manager-fededp"&gt;Release Manager @FedeDP&lt;/h4&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="changelog-item"&gt;
&lt;h2 class="title is-size-3 is-size-4-mobile"&gt;Version &lt;a href="https://github.com/falcosecurity/falco/tree/0.39.0-rc3" target="_blank"&gt;0.39.0-rc3&lt;/a&gt;&lt;/h2&gt;
&lt;div class="changelog-item-content content"&gt;
&lt;h3 class="title is-size-3 is-size-4-mobile"&gt;Download&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;</description></item></channel></rss>