build(deps): bump github.com/moby/buildkit from 0.9.2 to 0.11.4 by dependabot[bot] · Pull Request #76 · unacast/act
Bumps github.com/moby/buildkit from 0.9.2 to 0.11.4.
Release notes
Sourced from github.com/moby/buildkit's releases.
v0.11.4
https://hub.docker.com/r/moby/buildkit
Notable changes:
This release contains two security fixes.
Fix the issue where credentials inlined to Git URLs could end up in provenance attestation GHSA-gc89-7gcr-jxqc
Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly GHSA-hmfx-3pcx-653p #3651
Other updates
- Fix possible panic with writing annotations #3670
- Fix possible panic with passing nil frontend input #3659
- Fix file capabilities in merged snapshots by changing chown order #3671
v0.11.3
Welcome to the 0.11.3 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable Changes
- Builtin Dockerfile frontend updated to v1.5.2
- Fix not mounting optional secrets missing from build requests #3561
- Fix an issue with Github cache backend that could cause invalid range requests #3618
- Fix possible cache loading error when loading local cache created by BuildKit releases older than v0.10 #3605
- Fix issues with missing layer metadata in SBOMs in latest releases #3594
- Fix possible "digest not found" error on exporting build results #3566
- Make sure timezones are dropped on handling
SOURCE_DATE_EPOCH#3559Dependency Changes
- github.com/containerd/containerd 1709cfe273d9 -> v1.6.16
Previous release can be found at v0.11.2
v0.11.2
Welcome to the 0.11.2 release of buildkit!
Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.
Notable changes
- Update containerd patches to fix regression in handling push errors #3531
... (truncated)
Commits
3abd1efMerge pull request from GHSA-gc89-7gcr-jxqc7d45f99provenance: ensure URLs are redacted before written218e934Merge pull request #3676 from vvoland/sbomsupplements-hang-011e344f3atest/client: Close buildkit client0df0faaMerge pull request #3614 from crazy-max/v0.11_deprecate-buildinfo2590f95Merge pull request #3673 from tonistiigi/v0.11.4-picks97b37f9diffapply: do chown before xattrs17401b5Fix buildkitd panic when frontend input is nil.99aaa10fix a possible panic on cache837b4b2buildinfo: add BUILDKIT_BUILDINFO build arg- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)