🦅 Falco 0.42 Released — Faster, Smarter, and Ready for Forensics!

I’m excited to announce Falco 0.42.0, bringing major performance and observability improvements to your runtime security experience!

Key highlights

:movie_camera: Capture recording: record and replay Falco events for deeper forensic analysis, now easily inspectable with Stratoshark

:high_voltage: Performance boost: up to 30% faster thanks to the new “drop enter” syscalls optimization

:puzzle_piece: Plugin event schema validation: better compatibility and safer plugin interactions

:broom: Thread-table auto-purging: improved memory management for long-running Falco sessions

:receipt: static_fields support: easily attach custom static metadata to every event (perfect for tagging clusters, environments, or deployments)

:warning: Note: This release includes some breaking changes (for example, evt.dir is deprecated), so please review the upgrade notes before updating.

A huge thank you to Leonardo Di Giovanna and Iacopo Rozzo for leading this release and to all contributors who made it possible! :blue_heart:

:backhand_index_pointing_right: Read the full announcement here: Introducing Falco 0.42.0 | Falco