So Podman put v6.1.2 on the feed, dated September 16, 2026. We flagged it Important as a security fix. Recency wants the misc section: Buildah to v1.45.1, Common to v0.69.2, Image to v5.41.2, Storage to v1.64.1. Fine. Those are the names people screenshot when they skim a patch tag.
The line that matters, to the best of my understanding, is the Security block. This release addresses CVE-2025-11395, where importing images containing crafted layer tarballs with podman load, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host. Your AE forwards 6.1.2. A customer whose CI runners still accept untrusted images or volume archives starts asking whether load and volume import can write outside the container. That is the product change you track when you sell next to container tooling, not the version bump list.
There are two more CVEs in the same note: CVE-2026-79699 and CVE-2026-79705. Podman says they do not believe those are exploitable through the Podman command line. Kind of easy to paste all three into a security newsletter and sound thorough. Kind of useless when the partner ticket is the one CVE that names the commands.
I keep almost filing Podman under "container runtime bump, ignore." Kind of the wrong habit when you sell into teams that share runners or import images from partners. Tracking product change here means reading past the dependency bumps and asking which line changes a partner ticket. Let's say the talking point is not "6.1.2 shipped." It is load and volume import can overwrite host files under CVE-2025-11395, then yes mention the other two CVEs are listed but not believed CLI-exploitable. We pull it into a uniform entry shape at /sources/podman-releases. Same JSON as everything else. Recency still wants the Buildah bump. Recency is not the host overwrite.