Skip to content

build(deps): bump github.com/moby/buildkit from 0.11.3 to 0.11.4#10353

Merged
laurazard merged 1 commit intov2from
dependabot/go_modules/github.com/moby/buildkit-0.11.4
Mar 19, 2023
Merged

build(deps): bump github.com/moby/buildkit from 0.11.3 to 0.11.4#10353
laurazard merged 1 commit intov2from
dependabot/go_modules/github.com/moby/buildkit-0.11.4

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 7, 2023

Bumps github.com/moby/buildkit from 0.11.3 to 0.11.4.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.11.4

https://hub.docker.com/r/moby/buildkit

Notable changes:

This release contains two security fixes.

  • Fix the issue where credentials inlined to Git URLs could end up in provenance attestation GHSA-gc89-7gcr-jxqc

  • Containerd has been updated to 1.6.18 , fixing issue with supplementary groups not being set up properly GHSA-hmfx-3pcx-653p #3651

Other updates

  • Fix possible panic with writing annotations #3670
  • Fix possible panic with passing nil frontend input #3659
  • Fix file capabilities in merged snapshots by changing chown order #3671
Commits
  • 3abd1ef Merge pull request from GHSA-gc89-7gcr-jxqc
  • 7d45f99 provenance: ensure URLs are redacted before written
  • 218e934 Merge pull request #3676 from vvoland/sbomsupplements-hang-011
  • e344f3a test/client: Close buildkit client
  • 0df0faa Merge pull request #3614 from crazy-max/v0.11_deprecate-buildinfo
  • 2590f95 Merge pull request #3673 from tonistiigi/v0.11.4-picks
  • 97b37f9 diffapply: do chown before xattrs
  • 17401b5 Fix buildkitd panic when frontend input is nil.
  • 99aaa10 fix a possible panic on cache
  • 837b4b2 buildinfo: add BUILDKIT_BUILDINFO build arg
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 7, 2023
@codecov
Copy link

codecov bot commented Mar 7, 2023

Codecov Report

Patch coverage has no change and project coverage change: -0.04 ⚠️

Comparison is base (643557d) 53.39% compared to head (0b41df9) 53.36%.

Additional details and impacted files
@@            Coverage Diff             @@
##               v2   #10353      +/-   ##
==========================================
- Coverage   53.39%   53.36%   -0.04%     
==========================================
  Files         104      104              
  Lines        8939     8939              
==========================================
- Hits         4773     4770       -3     
- Misses       3646     3648       +2     
- Partials      520      521       +1     

see 1 file with indirect coverage changes

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report in Codecov by Sentry.
📢 Do you have feedback about the report comment? Let us know in this issue.

@lrascao
Copy link
Contributor

lrascao commented Mar 18, 2023

@dependabot rebase

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 18, 2023

Sorry, only users with push access can use that command.

@laurazard
Copy link
Member

@dependabot rebase

Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.11.3 to 0.11.4.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.11.3...v0.11.4)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/moby/buildkit-0.11.4 branch from 3096f58 to 0b41df9 Compare March 19, 2023 20:28
@laurazard laurazard enabled auto-merge March 19, 2023 20:28
@laurazard laurazard merged commit 9ec4397 into v2 Mar 19, 2023
@laurazard laurazard deleted the dependabot/go_modules/github.com/moby/buildkit-0.11.4 branch March 19, 2023 20:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants