Tonis Tiigi
0cf7592d41
vendor: update buildkit to v0.32.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-07-22 15:27:47 -07:00
Sebastiaan van Stijn
962c4d1780
vendor: golang.org/x/tools v0.46.0
...
full diff: https://github.com/golang/tools/compare/v0.45.0...v0.46.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
04c24b93df
vendor: golang.org/x/net v0.56.0
...
full diff: https://github.com/golang/net/compare/v0.55.0...v0.56.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
a271da13ea
vendor: golang.org/x/crypto v0.53.0
...
full diff: https://github.com/golang/crypto/compare/v0.52.0...v0.53.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
d551a606e9
vendor: golang.org/x/sync v0.21.0
...
full diff: https://github.com/golang/sync/compare/v0.20.0...v0.21.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:50 +02:00
Sebastiaan van Stijn
d2a2999949
vendor: golang.org/x/sys v0.46.0
...
full diff: https://github.com/golang/sys/compare/v0.45.0...v0.46.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-19 17:12:49 +02:00
CrazyMax
268dcf5917
vendor: update buildkit to v0.31.0-rc2
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-06-12 13:46:40 +02:00
Sopho Merkviladze
562b88ee69
bump golang.org/x/net to v0.55.0
...
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com >
2026-06-02 18:11:04 +04:00
Sopho Merkviladze
9952c6b807
bump golang.org/x/* dependencies
...
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com >
2026-05-28 23:22:34 +04:00
Tonis Tiigi
cb6566122b
vendor: update buildkit to v0.30.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-05-11 13:15:00 -07:00
Sebastiaan van Stijn
eaac97ea66
vendor: golang.org/x/net v0.52.0
...
full diff: https://cs.opensource.google/go/x/net/+/refs/tags/v0.50.0...refs/tags/v0.52.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
2700871d66
vendor: golang.org/x/mod v0.34.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn
3ad8f0891a
vendor: golang.org/x/sync v0.20.0
...
full diff: https://cs.opensource.google/go/x/sync/+/refs/tags/v0.19.0...refs/tags/v0.20.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-04-04 01:41:02 +02:00
Tonis Tiigi
eba72a35e4
vendor: update buildkit to v0.29.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-03-25 15:47:08 -07:00
Tonis Tiigi
55bef8178d
vendor: update buildkit to v0.28.0
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-03-03 12:17:01 -08:00
Tonis Tiigi
dd2a620465
vendor: update buildkit to v0.28.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-02-24 14:19:34 -08:00
Sebastiaan van Stijn
efe1aa593e
vendor: golang.org/x/mod v0.32.0
...
full diffs:
- https://cs.opensource.google/go/x/tools/+/refs/tags/v0.39.0...refs/tags/v0.41.0
- https://cs.opensource.google/go/x/mod/+/refs/tags/v0.31.0...refs/tags/v0.32.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-01-27 10:05:18 +01:00
Sebastiaan van Stijn
5d44afbda4
vendor: golang.org/x/crypto v0.47.0
...
full diffs:
- https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.46.0...refs/tags/v0.47.0
- https://cs.opensource.google/go/x/net/+/refs/tags/v0.48.0...refs/tags/v0.49.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn
95a1cb94b3
vendor: golang.org/x/tools v0.40.0
...
full diff: https://cs.opensource.google/go/x/tools/+/refs/tags/v0.39.0...refs/tags/v0.40.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn
214ebd8434
vendor: golang.org/x/term v0.39.0
...
full diff: https://cs.opensource.google/go/x/term/+/refs/tags/v0.38.0...refs/tags/v0.39.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn
40d068e12c
vendor: golang.org/x/sys v0.40.0
...
full diff: https://cs.opensource.google/go/x/sys/+/refs/tags/v0.39.0...refs/tags/v0.40.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-01-27 10:02:48 +01:00
Tonis Tiigi
d54f398c5d
vendor: update buildkit to v0.27.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-01-14 13:36:15 -08:00
Tonis Tiigi
87d4189039
policy: image signature verification support
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-01-14 09:03:42 -08:00
Tonis Tiigi
b2697ae933
policy: add git signature verification support
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-01-14 09:03:42 -08:00
Tonis Tiigi
93341aaeee
add rego integration to source policies
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-01-14 09:03:40 -08:00
Sebastiaan van Stijn
027fa165d0
vendor: golang.org/x/crypto v0.45.0
...
full diff: https://github.com/golang/crypto/compare/v0.44.0...v0.45.0
Hello gophers,
We have tagged version v0.45.0 of golang.org/x/crypto in order to address two
security issues.
This version fixes a vulnerability in the golang.org/x/crypto/ssh package and a
vulnerability in the golang.org/x/crypto/ssh/agent package which could cause
programs to consume unbounded memory or panic respectively.
SSH servers parsing GSSAPI authentication requests don't validate the number of
mechanisms specified in the request, allowing an attacker to cause unbounded
memory consumption.
Thanks to Jakub Ciolek for reporting this issue.
This is CVE-2025-58181 and Go issue https://go.dev/issue/76363 .
SSH Agent servers do not validate the size of messages when processing new
identity requests, which may cause the program to panic if the message is
malformed due to an out of bounds read.
Thanks to Jakub Ciolek for reporting this issue.
This is CVE-2025-47914 and Go issue https://go.dev/issue/76364 .
Cheers, Go Security team
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 19:17:06 +01:00
Sebastiaan van Stijn
a2a2819d7d
vendor: golang.org/x/net v0.47.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 19:13:50 +01:00
Sebastiaan van Stijn
ae3eed7b80
vendor: golang.org/x/text v0.31.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 19:12:17 +01:00
Sebastiaan van Stijn
3f5c571f69
golang.org/x/term v0.37.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 19:09:59 +01:00
Sebastiaan van Stijn
b20a9ecf67
vendor: golang.org/x/sync v0.18.0
...
full diff: https://github.com/golang/sync/compare/v0.17.0...v0.18.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 18:47:50 +01:00
Sebastiaan van Stijn
3858752e0a
vendor: golang.org/x/sys v0.38.0
...
- cpu: add HPDS, LOR, PAN detection for arm64
- cpu: also use MRS instruction in getmmfr1
- cpu: use MRS instruction to read arm64 system registers
- unix: add consts for ELF handling
- unix: add SetMemPolicy and its mode/flag values
- unix: add SizeofNhmsg and SizeofNexthopGrp
- windows: add iphlpapi routing functions
full diff: https://github.com/golang/sys/compare/v0.37.0...v0.38.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-11-27 18:45:58 +01:00
Tonis Tiigi
faf30a2177
vendor: update containerd to v2.2.0-rc.1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2025-11-05 10:24:42 -08:00
CrazyMax and CrazyMax
228a816bbb
vendor: github.com/moby/buildkit@master 9b6f60ac8bf9
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2025-10-11 23:03:13 +02:00
CrazyMax
f5665d2e42
vendor: update hcl dependencies
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2025-09-10 10:00:58 +02:00
Tonis Tiigi
ec3b99180b
vendor: update buildkit to v0.24.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2025-08-27 13:39:14 -07:00
Guillaume Lours
e99190b8b2
bump compose-go to version v2.7.1
...
Signed-off-by: Guillaume Lours <705411+glours@users.noreply.github.com >
2025-07-01 12:26:25 +02:00
Jonathan A. Sternberg
e1adeee898
vendor: github.com/moby/buildkit v0.23.0-rc1
...
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com >
2025-06-11 16:29:31 -05:00
Sebastiaan van Stijn
67ccbd06f6
vendor: golang.org/x/oauth2 v0.29.0
...
notable changes
- fixes CVE-2025-22868
- oauth2.go: use a more straightforward return value
- oauth2: Deep copy context client in NewClient
- jws: improve fix for CVE-2025-22868
full diff: https://github.com/golang/oauth2/compare/v0.23.0...v0.29.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-04-22 12:26:36 +02:00
Guillaume Lours
0b4e624aaa
bump compose-go to version v2.6.0
...
Signed-off-by: Guillaume Lours <705411+glours@users.noreply.github.com >
2025-04-10 18:04:00 +02:00
Jonathan A. Sternberg
8fb1157b5f
vendor: github.com/moby/buildkit v0.21.0-rc1
...
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com >
2025-04-09 10:28:03 -05:00
Sebastiaan van Stijn
d25e260d2e
vendor: github.com/docker/cli v28.0.4
...
This removes Notary / Docker Content Trust related (indirect)
dependencies;
Before:
ls -l bin/build/
total 131200
-rwxr-xr-x 1 thajeztah staff 67039266 Mar 21 09:20 buildx*
ls -lh bin/build/
total 131200
-rwxr-xr-x 1 thajeztah staff 64M Mar 21 09:20 buildx*
After:
ls -l bin/build/
total 127288
-rwxr-xr-x 1 thajeztah staff 65168450 Mar 21 09:22 buildx*
ls -lh bin/build/
total 127288
-rwxr-xr-x 1 thajeztah staff 62M Mar 21 09:22 buildx*
Difference: `67039266 - 65168450 = 1870816` (1.87 MB)
full diff: https://github.com/docker/cli/compare/v28.0.2...v28.0.4
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-25 18:45:44 +01:00
Sebastiaan van Stijn
689bea7963
vendor: golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f
...
full diff: https://github.com/golang/exp/compare/701f63a606c0...2d47ceb2692f
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-10 11:06:22 +01:00
Sebastiaan van Stijn
ec440c4574
vendor: golang.org/x/sys v0.29.0
...
full diff: https://github.com/golang/sys/compare/v0.28.0...v0.29.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-10 11:05:51 +01:00
Tonis Tiigi
44fa243d58
vendor: update buildkit to v0.19.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2025-01-14 14:24:38 -08:00
Tonis Tiigi
6fcc6853d9
vendor: update buildkit to v0.17.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-28 15:39:50 -07:00
Jonathan A. Sternberg
b35a0f4718
protobuf: remove gogoproto
...
Removes gogo/protobuf from buildx and updates to a version of
moby/buildkit where gogo is removed.
This also changes how the proto files are generated. This is because
newer versions of protobuf are more strict about name conflicts. If two
files have the same name (even if they are relative paths) and are used
in different protoc commands, they'll conflict in the registry.
Since protobuf file generation doesn't work very well with
`paths=source_relative`, this removes the `go:generate` expression and
just relies on the dockerfile to perform the generation.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com >
2024-10-02 15:51:59 -05:00
CrazyMax
4b27fb3022
vendor: update buildkit to 664c2b469f19
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2024-08-11 09:46:35 +02:00
CrazyMax
0fb0b6db0d
vendor: update buildkit to v0.15.1
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2024-07-25 15:57:49 +02:00
Sebastiaan van Stijn
d296d5d46a
vendor: google.golang.org/appengine v1.6.8
...
full diff: https://github.com/golang/appengine/compare/v1.6.7...v1.6.8
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-07-15 12:47:27 +02:00
Tonis Tiigi
50aa895477
vendor: update buildkit to v0.15.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-07-03 12:43:04 -07:00