Bump github.com/moby/buildkit from 0.11.6 to 0.12.5
Bumps github.com/moby/buildkit from 0.11.6 to 0.12.5.
Release notes
Sourced from github.com/moby/buildkit's releases.
v0.12.5
https://hub.docker.com/r/moby/buildkit
Notable changes:
This release contains following security fixes:
Runc has been updated to v1.1.12 addressing https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
Fix possible race condition with accessing subpaths from cache mounts https://github.com/moby/buildkit/security/advisories/GHSA-m3r6-h7wv-7xxv
Fix possible host system access from mount stub cleaner https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8
Fix interactive containers API validation against entitlements https://github.com/moby/buildkit/security/advisories/GHSA-wr6v-9f75-vh2g
Fix possible panic when incorrect parameters sent from frontend https://github.com/moby/buildkit/security/advisories/GHSA-9p26-698r-w4hx
v0.12.4
Welcome to the 0.12.4 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable changes
- Fix possible concurrent map access on remote cache export #4346
- Fix hang on debug server listener #4361
- Fix possible deadlock in History API under high number of parallel builds #4362
- Fix possible panic on handling deleted records in History API #4451
- Fix possible data corruption in zstd library #4372
v0.12.3
Welcome to the 0.12.3 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable changes
- Fix possible duplicate source files in provenance attestation for chained builds #4190
- Fix possible negative step time in progressbar for step shared with other build request #4183
- Fix properly closing history and cache DB on shutdown to avoid corruption #4185 #4189
- Fix incorrect error handling for invalid HTTP source URLs #4201
- Fix fallback cases for ambiguous insecure configuration provided for registry used as push target. #4299
- Fix possible data race with parallel image config resolves #4157
- Fix regression in v0.12 for clients waiting on buildkitd to become available #4200
- Fix Cgroup NS handling for hosts supporting only CgroupV1 #4308
v0.12.2
Welcome to the 0.12.2 release of buildkit!
... (truncated)
Commits
bac3f2bupdate runc to v1.1.12f781267exec: add extra validation for submount sourcesd089e0boci: fix error handling on submount calls00fe637executor: recheck mount stub path within root after container run92cc595llbsolver: make sure interactive container API validates entitlements5026d95gateway: pass executor with build and not access worker directly7718bd5pb: add extra validation to protobuf typese1924dcsourcepolicy: add validations for nil values96663ddexporter: add validation for platforms key value481d9c4exporter: add validation for invalid platorm- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.