Skip to content
This repository has been archived by the owner on Sep 19, 2023. It is now read-only.

Bump github.com/moby/buildkit from 0.10.6 to 0.11.5 #45

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 27, 2023

Bumps github.com/moby/buildkit from 0.10.6 to 0.11.5.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.11.5

https://hub.docker.com/r/moby/buildkit

Notable changes:

  • Fix process termination handling to Runc when running interactive processes #3722
  • Fix gateway exec tty cleanup on context.Canceled #3658
  • Register builds before recording build history to avoid possible timeout error #3726
  • Fix performance regression in creating LLB graphs #3732
  • Fix sorting of build history records for GC #3733
  • Fix an issue where linking builds with providing LLB inputs dropped the original source information for such inputs #3678
  • Fix running BuildKit on BottleRocket OS #3697

v0.11.4

https://hub.docker.com/r/moby/buildkit

Notable changes:

This release contains two security fixes.

  • Fix the issue where credentials inlined to Git URLs could end up in provenance attestation GHSA-gc89-7gcr-jxqc

  • Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly GHSA-hmfx-3pcx-653p #3651

Other updates

  • Fix possible panic with writing annotations #3670
  • Fix possible panic with passing nil frontend input #3659
  • Fix file capabilities in merged snapshots by changing chown order #3671

v0.11.3

Welcome to the 0.11.3 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Notable Changes

  • Builtin Dockerfile frontend updated to v1.5.2
  • Fix not mounting optional secrets missing from build requests #3561
  • Fix an issue with Github cache backend that could cause invalid range requests #3618
  • Fix possible cache loading error when loading local cache created by BuildKit releases older than v0.10 #3605
  • Fix issues with missing layer metadata in SBOMs in latest releases #3594
  • Fix possible "digest not found" error on exporting build results #3566
  • Make sure timezones are dropped on handling SOURCE_DATE_EPOCH #3559

Dependency Changes

... (truncated)

Commits
  • 252ae63 Merge pull request #3734 from tonistiigi/v0.11.5-picks
  • 103bf22 llbsolver: fix sorting of history records
  • 90ff220 llbsolver: Fix performance of recomputeDigests
  • 950e06d fix gateway exec tty cleanup on context.Canceled
  • 770c9d1 Register builds before recording build history
  • 2f79b14 fix process termination handling for runc exec
  • a0f2992 Merge pull request #3701 from AkihiroSuda/cherrypick-3697
  • 237fee9 Merge pull request #3713 from crazy-max/v0.11_backport_test-feature-envs
  • 37f2634 integration: missing mergeDiff compat check
  • 837e0e9 integration: split feature compat check for subtests
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.10.6 to 0.11.5.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.10.6...v0.11.5)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 27, 2023
@dependabot dependabot bot requested a review from haines March 27, 2023 05:57
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Apr 24, 2023

Superseded by #46.

@dependabot dependabot bot closed this Apr 24, 2023
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/moby/buildkit-0.11.5 branch April 24, 2023 05:58
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants