Welcome to the v0.33.1 release of buildkit!
Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.
Contributors
- Tõnis Tiigi
- CrazyMax
- Sebastiaan van Stijn
Notable Changes
- Built-in Dockerfile frontend has been updated to v1.27.1 changelog.
- Fix proxy CA cleanup so build steps cannot redirect it outside the build rootfs, block it with a special file, or succeed when cleanup fails. https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x
- Fix a daemon panic when a build requests CDI devices while CDI support is disabled. Optional devices are ignored; required devices produce an error. https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf
- Verify container blob contents against their claimed digest before caching them. This protects shared caches from unverified blobs supplied through the low-level LLB API. https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv
- Verify applied image layer DiffIDs, bind lazy stargz snapshots to their verified TOC digest, and isolate legacy layer snapshots. Image source cache keys no longer rely on unverified DiffIDs. https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3
- Prevent malicious external frontends from crashing the daemon through gateway container lifecycle races or malformed requests and definitions. https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8
- Reject special files in daemon-side snapshot reads and replace existing special files safely in LLB
mkfileoperations. https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2 - Reject malformed LLB file operations with invalid symlink owner inputs instead of allowing a daemon panic. https://github.com/moby/buildkit/security/advisories/GHSA-fjj4-h6vf-m9hj
- Reject malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic. https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq
- Limit Dockerfile,
.dockerignore, gateway file, and nested LLB definition reads to prevent oversized inputs from exhausting daemon memory. https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp - Apply source policies to Git bundle locators and reject Git full remote URLs that do not match the source identifier. https://github.com/moby/buildkit/security/advisories/GHSA-66hf-6vf5-87hc
Dependency Changes
- github.com/containerd/containerd/v2 v2.3.4 -> v2.3.6
- golang.org/x/crypto v0.55.0 -> v0.56.0
Previous release can be found at v0.33.0