Skip to content
This repository has been archived by the owner on Sep 19, 2023. It is now read-only.

Bump github.com/moby/buildkit from 0.10.6 to 0.11.6 #46

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 24, 2023

Bumps github.com/moby/buildkit from 0.10.6 to 0.11.6.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.11.6

https://hub.docker.com/r/moby/buildkit

Notable changes:

  • Revert previous signal handling fix to make sure no process leaks happen. The signaling issue will be fixed in the next feature release. moby/buildkit#3757
  • Update runc to v1.1.5 for security moby/buildkit#3763
  • Update containerd to v1.6.20 . Brings in fix for not writing local user/group names in differ. #3736
  • Fix possible "duplicate output 0" error on parallel builds #3774
  • Fix token management for servers that don't return proper IssuedAt value #3779
  • Fix SBOM and provenance processing for certain nil-result cases #3805

v0.11.5

https://hub.docker.com/r/moby/buildkit

Notable changes:

  • Fix process termination handling to Runc when running interactive processes #3722
  • Fix gateway exec tty cleanup on context.Canceled #3658
  • Register builds before recording build history to avoid possible timeout error #3726
  • Fix performance regression in creating LLB graphs #3732
  • Fix sorting of build history records for GC #3733
  • Fix an issue where linking builds with providing LLB inputs dropped the original source information for such inputs #3678
  • Fix running BuildKit on BottleRocket OS #3697

v0.11.4

https://hub.docker.com/r/moby/buildkit

Notable changes:

This release contains two security fixes.

  • Fix the issue where credentials inlined to Git URLs could end up in provenance attestation GHSA-gc89-7gcr-jxqc

  • Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly GHSA-hmfx-3pcx-653p #3651

Other updates

  • Fix possible panic with writing annotations #3670
  • Fix possible panic with passing nil frontend input #3659
  • Fix file capabilities in merged snapshots by changing chown order #3671

v0.11.3

Welcome to the 0.11.3 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Notable Changes

... (truncated)

Commits
  • 2951a28 Merge pull request #3810 from tonistiigi/v0.11.6-picks
  • c48a6bc Fix bearer token expiration check (fixes #3779)
  • 7ddae62 solver: skip sbom post processor if result is nil
  • 11a0070 Merge pull request #3763 from AkihiroSuda/runc-1.1.5-0.11
  • ae5a76a Dockerfile: RUNC_VERSION=v1.1.5
  • 58fc08b Merge pull request #3736 from thaJeztah/0.11_containerd_1.6.20
  • 664059a Merge pull request #3774 from tonistiigi/v0.11-fileopsolver-unique
  • a1ae2bd fileop: create new fileOpSolver instance per Exec call
  • 5572c69 [0.11] vendor github.com/containerd/containerd v1.6.20
  • 5cdc5ce [0.11] vendor: github.com/opencontainers/image-spec v1.1.0-rc2.0.202210051852...
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.10.6 to 0.11.6.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.10.6...v0.11.6)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Apr 24, 2023
@dependabot dependabot bot requested a review from haines April 24, 2023 05:57
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 19, 2023

Superseded by #51.

@dependabot dependabot bot closed this Sep 19, 2023
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/moby/buildkit-0.11.6 branch September 19, 2023 11:04
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants