Sebastiaan van Stijn
0ff357e4be
vendor: github.com/segmentio/asm v1.2.1
...
- LICENSE CHANGE: MIT to MIT-0 (No Attribution)
- replace arm64 macro to please go vet
full diff: https://github.com/segmentio/asm/compare/v1.2.0...v1.2.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:33 +02:00
CrazyMax and GitHub
9587b741bc
Merge pull request #3912 from thaJeztah/bump_moby
...
vendor: github.com/docker/cli v29.6.1
2026-07-01 15:15:02 +02:00
Sebastiaan van Stijn
d27d845f75
vendor: github.com/docker/cli v29.6.1
...
full diff: https://github.com/docker/cli/compare/v29.5.3...v29.6.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 14:43:19 +02:00
Sebastiaan van Stijn
e1e5963dae
vendor: github.com/containerd/containerd/v2 v2.2.5
...
- full diff: https://github.com/containerd/containerd/compare/v2.2.4...v2.2.5
- release notes: https://github.com/containerd/containerd/releases/tag/v2.2.5
The fifth patch release for containerd 2.2 contains various fixes
and updates including security patches.
- CVE-2026-50195 / [GHSA-cvxm-645q-p574] CRI: checkpoint import allows local image tag poisoning
- CVE-2026-53488 / [GHSA-xhf5-7wjv-pqxp] CRI: image-config LABEL flows to host-root command execution from an image pull
- CVE-2026-53492 / [GHSA-33vj-92qq-66hc] CRI: CDI annotation smuggling during CRI checkpoint restore
- CVE-2026-53489 / [GHSA-rgh6-rfwx-v388] CRI: Arbitrary host file read via symlink following in CRI checkpoint restore
- CVE-2026-47262 / [GHSA-jpcc-p29g-p8mq] containerd image-triggered runtime DoS via unbounded group parsing
[GHSA-cvxm-645q-p574]: https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574
[GHSA-xhf5-7wjv-pqxp]: https://github.com/containerd/containerd/security/advisories/GHSA-xhf5-7wjv-pqxp
[GHSA-33vj-92qq-66hc]: https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc
[GHSA-rgh6-rfwx-v388]: https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388
[GHSA-jpcc-p29g-p8mq]: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-23 09:27:04 +02:00
Sebastiaan van Stijn
962c4d1780
vendor: golang.org/x/tools v0.46.0
...
full diff: https://github.com/golang/tools/compare/v0.45.0...v0.46.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
04c24b93df
vendor: golang.org/x/net v0.56.0
...
full diff: https://github.com/golang/net/compare/v0.55.0...v0.56.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
a271da13ea
vendor: golang.org/x/crypto v0.53.0
...
full diff: https://github.com/golang/crypto/compare/v0.52.0...v0.53.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
7609bf8845
vendor: golang.org/x/text v0.38.0
...
full diff: https://github.com/golang/text/compare/v0.37.0...v0.38.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
d551a606e9
vendor: golang.org/x/sync v0.21.0
...
full diff: https://github.com/golang/sync/compare/v0.20.0...v0.21.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
ad0a622e24
vendor: golang.org/x/mod v0.37.0
...
full diff: https://github.com/golang/mod/compare/v0.36.0...v0.37.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:49 +02:00
Sebastiaan van Stijn
8d182fad32
vendor: golang.org/x/term v0.44.0
...
full diff: https://github.com/golang/term/compare/v0.43.0...v0.44.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:49 +02:00
Sebastiaan van Stijn
d2a2999949
vendor: golang.org/x/sys v0.46.0
...
full diff: https://github.com/golang/sys/compare/v0.45.0...v0.46.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:49 +02:00
Tonis Tiigi
af83612e3f
vendor: update buildkit to v0.31.0
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-06-17 11:51:42 -07:00
Sebastiaan van Stijn
68fd340247
vendor: go.opentelemetry.io/otel/exporters v1.44.0
...
removes the semconv v1.40.0 dependency
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-15 14:13:52 +02:00
Tõnis Tiigi and GitHub
b4b3437a30
Merge pull request #3898 from crazy-max/compose-go-2.11.0
...
vendor: update compose-go to v2.11.0
2026-06-12 15:40:38 -07:00
CrazyMax
268dcf5917
vendor: update buildkit to v0.31.0-rc2
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-06-12 13:46:40 +02:00
CrazyMax
803403710a
vendor: update compose-go to v2.11.0
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-06-11 11:13:52 +02:00
Tonis Tiigi
b5cf212276
vendor: update buildkit to v0.31.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-06-10 14:19:03 -07:00
CrazyMax
1916210ddc
vendor: update buildkit to f449174742bf
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-06-10 16:41:09 +02:00
Tonis Tiigi
58a5a2cd60
vendor: update buildkit to 41c29fffe299
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-06-09 19:44:00 -07:00
Sopho Merkviladze
562b88ee69
bump golang.org/x/net to v0.55.0
...
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com >
2026-06-02 18:11:04 +04:00
Sopho Merkviladze
9952c6b807
bump golang.org/x/* dependencies
...
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com >
2026-05-28 23:22:34 +04:00
dependabot[bot] and GitHub
cb2b59576e
build(deps): bump github.com/containerd/containerd/v2
...
Bumps the go_modules group with 1 update in the / directory: [github.com/containerd/containerd/v2](https://github.com/containerd/containerd ).
Updates `github.com/containerd/containerd/v2` from 2.2.3 to 2.2.4
- [Release notes](https://github.com/containerd/containerd/releases )
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md )
- [Commits](https://github.com/containerd/containerd/compare/v2.2.3...v2.2.4 )
---
updated-dependencies:
- dependency-name: github.com/containerd/containerd/v2
dependency-version: 2.2.4
dependency-type: direct:production
dependency-group: go_modules
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-21 22:02:05 +00:00
Sebastiaan van Stijn
587111d392
vendor: github.com/docker/cli v29.5.1
...
full diff: https://github.com/docker/cli/compare/v29.4.3...v29.5.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-18 20:49:19 +02:00
Tõnis Tiigi and GitHub
d9d58cb5b0
Merge pull request #3839 from thaJeztah/bump_creds_helper
...
vendor: github.com/docker/docker-credential-helpers v0.9.7
2026-05-14 11:02:51 -07:00
CrazyMax
9372cc4b5f
vendor: update buildkit to v0.30.0
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-05-13 15:11:06 +02:00
Tonis Tiigi
cb6566122b
vendor: update buildkit to v0.30.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-05-11 13:15:00 -07:00
Sebastiaan van Stijn
5378e2a2dd
vendor: github.com/docker/docker-credential-helpers v0.9.7
...
no code-changes; only updates go version
full diff: https://github.com/docker/docker-credential-helpers/compare/v0.9.6...v0.9.7
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-08 14:54:48 +02:00
Tonis Tiigi
a3147eba54
vendor: update buildkit to v0.30.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-05-06 15:06:54 -07:00
Sebastiaan van Stijn
76ba2fac5c
driver/docker-container: remove uses of jsonmessage
...
This function was always using `io.Discard` for printing the progress,
so we can use the `Wait()` method, which reads the stream, returning
any error (similar to jsonmessage.DisplayJSONMessagesStream), and
closes the stream either if the context is cancelled, or if the
stream ends.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-21 13:35:39 +02:00
Sebastiaan van Stijn
d45c770d5e
vendor: github.com/docker/cli v29.4.1
...
full diff: https://github.com/docker/cli/compare/v29.4.0...v29.4.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-21 12:17:00 +02:00
Sebastiaan van Stijn
650f72ca74
vendor: github.com/mattn/go-runewidth v0.0.23
...
full diff: https://github.com/mattn/go-runewidth/compare/v0.0.22...v0.0.23
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-21 12:17:00 +02:00
Sebastiaan van Stijn
a2e6003124
vendor: github.com/moby/moby/client v0.4.1, moby/api v1.54.2
...
- https://github.com/moby/moby/compare/api/v1.54.1...api/v1.54.2
- https://github.com/moby/moby/compare/client/v0.4.0...client/v0.4.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-21 12:16:59 +02:00
Sebastiaan van Stijn
478d9b19a2
vendor: github.com/docker/go-connections v0.7.0
...
full diff: https://github.com/docker/go-connections/compare/v0.6.0...v0.7.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-21 12:16:59 +02:00
CrazyMax
b7061891c5
vendor: k8s v0.35.4
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-04-21 11:18:40 +02:00
CrazyMax
4f89a2407a
gitutil: use BuildKit urlutil.RedactCredentials for remote URLs
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-04-09 15:04:37 +02:00
CrazyMax
3124b3c839
vendor: update buildkit to a243ce438aee
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-04-09 14:40:14 +02:00
Sebastiaan van Stijn
0b0843233b
vendor: github.com/docker/cli v29.4.0
...
full diff: https://github.com/docker/cli/compare/v29.3.1...v29.4.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-07 11:52:07 +02:00
Sebastiaan van Stijn
2da27cedb5
vendor: github.com/mattn/go-runewidth v0.0.22
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
eaac97ea66
vendor: golang.org/x/net v0.52.0
...
full diff: https://cs.opensource.google/go/x/net/+/refs/tags/v0.50.0...refs/tags/v0.52.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
df41850e26
vendor: golang.org/x/time v0.15.0
...
full diff: https://cs.opensource.google/go/x/time/+/refs/tags/v0.14.0...refs/tags/v0.15.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
db4fa7c158
vendor: golang.org/x/text v0.35.0
...
full diff: https://cs.opensource.google/go/x/text/+/refs/tags/v0.34.0...refs/tags/v0.35.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
2700871d66
vendor: golang.org/x/mod v0.34.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
3ad8f0891a
vendor: golang.org/x/sync v0.20.0
...
full diff: https://cs.opensource.google/go/x/sync/+/refs/tags/v0.19.0...refs/tags/v0.20.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
63b4d001aa
vendor: go.opentelemetry.io/otel v1.42.0, otel/contrib v1.67.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:01 +02:00
Tõnis Tiigi and GitHub
b180175396
Merge pull request #3779 from thaJeztah/bump_moby
...
vendor: moby/client v0.4.0, moby/api v1.54.1
2026-04-03 11:36:47 -07:00
Jonathan A. Sternberg
d781c83cec
commands: micro optimization for source date epoch
...
Avoids the call to `os.Getenv` when it is unnecessary because it would
be overwritten anyway.
Removes the comments about moving environment variable parsing to a
method for use by library consumers. That method exists in containerd
and this set of code doesn't actually perform any parsing since the
parsing of this time is done within buildkit and not on the client.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com >
2026-04-03 10:02:50 -05:00
Sebastiaan van Stijn
3b630c6437
vendor: moby/client v0.4.0, moby/api v1.54.1
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-03 16:05:48 +02:00
Guillaume Lours
8a01076b67
bump compose-go to version v2.10.2
...
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com >
2026-04-03 12:15:27 +02:00
CrazyMax
fdef3304af
vendor: update buildkit to v0.29.0
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-03-31 14:52:21 +02:00