Skip to content

chore: Bump github.com/moby/buildkit from 0.9.3 to 0.11.6#165

Closed
dependabot[bot] wants to merge 1 commit intomainlinefrom
dependabot/go_modules/github.com/moby/buildkit-0.11.6
Closed

chore: Bump github.com/moby/buildkit from 0.9.3 to 0.11.6#165
dependabot[bot] wants to merge 1 commit intomainlinefrom
dependabot/go_modules/github.com/moby/buildkit-0.11.6

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot bot commented on behalf of github Apr 24, 2023

Bumps github.com/moby/buildkit from 0.9.3 to 0.11.6.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.11.6

https://hub.docker.com/r/moby/buildkit

Notable changes:

  • Revert previous signal handling fix to make sure no process leaks happen. The signaling issue will be fixed in the next feature release. moby/buildkit#3757
  • Update runc to v1.1.5 for security moby/buildkit#3763
  • Update containerd to v1.6.20 . Brings in fix for not writing local user/group names in differ. #3736
  • Fix possible "duplicate output 0" error on parallel builds #3774
  • Fix token management for servers that don't return proper IssuedAt value #3779
  • Fix SBOM and provenance processing for certain nil-result cases #3805

v0.11.5

https://hub.docker.com/r/moby/buildkit

Notable changes:

  • Fix process termination handling to Runc when running interactive processes #3722
  • Fix gateway exec tty cleanup on context.Canceled #3658
  • Register builds before recording build history to avoid possible timeout error #3726
  • Fix performance regression in creating LLB graphs #3732
  • Fix sorting of build history records for GC #3733
  • Fix an issue where linking builds with providing LLB inputs dropped the original source information for such inputs #3678
  • Fix running BuildKit on BottleRocket OS #3697

v0.11.4

https://hub.docker.com/r/moby/buildkit

Notable changes:

This release contains two security fixes.

  • Fix the issue where credentials inlined to Git URLs could end up in provenance attestation GHSA-gc89-7gcr-jxqc

  • Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly GHSA-hmfx-3pcx-653p #3651

Other updates

  • Fix possible panic with writing annotations #3670
  • Fix possible panic with passing nil frontend input #3659
  • Fix file capabilities in merged snapshots by changing chown order #3671

v0.11.3

Welcome to the 0.11.3 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Notable Changes

... (truncated)

Commits
  • 2951a28 Merge pull request #3810 from tonistiigi/v0.11.6-picks
  • c48a6bc Fix bearer token expiration check (fixes #3779)
  • 7ddae62 solver: skip sbom post processor if result is nil
  • 11a0070 Merge pull request #3763 from AkihiroSuda/runc-1.1.5-0.11
  • ae5a76a Dockerfile: RUNC_VERSION=v1.1.5
  • 58fc08b Merge pull request #3736 from thaJeztah/0.11_containerd_1.6.20
  • 664059a Merge pull request #3774 from tonistiigi/v0.11-fileopsolver-unique
  • a1ae2bd fileop: create new fileOpSolver instance per Exec call
  • 5572c69 [0.11] vendor github.com/containerd/containerd v1.6.20
  • 5cdc5ce [0.11] vendor: github.com/opencontainers/image-spec v1.1.0-rc2.0.202210051852...
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.9.3 to 0.11.6.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.9.3...v0.11.6)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 24, 2023
@github-actions
Copy link
Copy Markdown

🍕 Here are the new binary sizes!

Name New size (kiB) size (kiB) Delta (%)
macOS (amd) 50536 50328 +0.41
macOS (arm) 50724 50516 +0.41
linux (amd) 44484 44304 +0.41
linux (arm) 42820 42564 +0.60
windows (amd) 41368 41204 +0.40

@dependabot @github
Copy link
Copy Markdown
Author

dependabot bot commented on behalf of github Jul 17, 2023

Superseded by #198.

@dependabot dependabot bot closed this Jul 17, 2023
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/moby/buildkit-0.11.6 branch July 17, 2023 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants