chore(deps): bump github.com/moby/buildkit from 0.10.4 to 0.11.4
Bumps github.com/moby/buildkit from 0.10.4 to 0.11.4.
Release notes
Sourced from github.com/moby/buildkit's releases.
v0.11.4
https://hub.docker.com/r/moby/buildkit
Notable changes:
This release contains two security fixes.
Fix the issue where credentials inlined to Git URLs could end up in provenance attestation https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc
Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p #3651
Other updates
- Fix possible panic with writing annotations #3670
- Fix possible panic with passing nil frontend input #3659
- Fix file capabilities in merged snapshots by changing chown order #3671
v0.11.3
Welcome to the 0.11.3 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable Changes
- Builtin Dockerfile frontend updated to v1.5.2
- Fix not mounting optional secrets missing from build requests #3561
- Fix an issue with Github cache backend that could cause invalid range requests #3618
- Fix possible cache loading error when loading local cache created by BuildKit releases older than v0.10 #3605
- Fix issues with missing layer metadata in SBOMs in latest releases #3594
- Fix possible "digest not found" error on exporting build results #3566
- Make sure timezones are dropped on handling
SOURCE_DATE_EPOCH#3559Dependency Changes
- github.com/containerd/containerd 1709cfe273d9 -> v1.6.16
Previous release can be found at v0.11.2
v0.11.2
Welcome to the 0.11.2 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable changes
- Update containerd patches to fix regression in handling push errors #3531
... (truncated)
Commits
3abd1efMerge pull request from GHSA-gc89-7gcr-jxqc7d45f99provenance: ensure URLs are redacted before written218e934Merge pull request #3676 from vvoland/sbomsupplements-hang-011e344f3atest/client: Close buildkit client0df0faaMerge pull request #3614 from crazy-max/v0.11_deprecate-buildinfo2590f95Merge pull request #3673 from tonistiigi/v0.11.4-picks97b37f9diffapply: do chown before xattrs17401b5Fix buildkitd panic when frontend input is nil.99aaa10fix a possible panic on cache837b4b2buildinfo: add BUILDKIT_BUILDINFO build arg- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.