MohammadHasan Akbari
877de7edf2
remote: prefer servername for grpc authority
...
When the servername driver-opt is set it is also used for TLS SNI and
certificate validation, so use it for the gRPC ":authority" pseudo-header
as well, falling back to the endpoint host otherwise. This matches how the
buildkit client derives the authority from the server name when TLS
credentials are supplied.
Since the driver terminates TLS in its own dialer, the authority is set
explicitly via client.WithGRPCDialOption(grpc.WithAuthority(...)).
Signed-off-by: MohammadHasan Akbari <jarqvi.jarqvi@gmail.com >
2026-07-11 10:17:12 +04:00
dependabot[bot] and GitHub
d147db5318
build(deps): bump docker/github-builder/.github/workflows/bake.yml
...
Bumps [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ) from 1.12.0 to 1.13.0.
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](https://github.com/docker/github-builder/compare/5f637c833aa76bc99372a1dc9a6f8bcd8056fb85...c4a1b216d96a8c85b45a9974b37857828274c808 )
---
updated-dependencies:
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.13.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-10 18:38:40 +00:00
dependabot[bot] and GitHub
7443506320
build(deps): bump the codeql-actions group with 4 updates
...
Bumps the codeql-actions group with 4 updates: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ), [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ) and [github/codeql-action/analyze](https://github.com/github/codeql-action ).
Updates `github/codeql-action/upload-sarif` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9 )
Updates `github/codeql-action/init` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9 )
Updates `github/codeql-action/autobuild` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9 )
Updates `github/codeql-action/analyze` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-10 18:38:19 +00:00
CrazyMax and GitHub
1f2cef18b8
Merge pull request #3947 from docker/dependabot/github_actions/actions/labeler-6.2.0
...
build(deps): bump actions/labeler from 6.1.0 to 6.2.0
2026-07-10 16:17:37 +02:00
dependabot[bot] and GitHub
331907ac99
build(deps): bump actions/labeler from 6.1.0 to 6.2.0
...
Bumps [actions/labeler](https://github.com/actions/labeler ) from 6.1.0 to 6.2.0.
- [Release notes](https://github.com/actions/labeler/releases )
- [Commits](https://github.com/actions/labeler/compare/f27b608878404679385c85cfa523b85ccb86e213...b8dd2d9be0f68b860e7dae5dae7d772984eacd6d )
---
updated-dependencies:
- dependency-name: actions/labeler
dependency-version: 6.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 18:38:00 +00:00
CrazyMax and GitHub
32a1eb033a
Merge pull request #3946 from thaJeztah/rm_go_reportcard
...
README: remove Go Report Card badge
2026-07-09 09:48:25 +02:00
Sebastiaan van Stijn
ade3d75607
README: remove Go Report Card badge
...
The project was sunset;
> After more than a decade of serving the ecosystem, the time
> has come to sunset Go Report Card. Following the loss of our
> primary infrastructure sponsor, maintaining the web app is
> no longer sustainable.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-09 01:04:56 +02:00
Tõnis Tiigi and GitHub
5964c80ed3
Merge pull request #3913 from thaJeztah/bump_opa
...
vendor: github.com/open-policy-agent/opa v1.14.1
2026-07-08 08:54:57 -07:00
Areeb Ahmed
ec41ad745d
fix random pod spread
...
Signed-off-by: Areeb Ahmed <areebahmed0709@gmail.com >
2026-07-08 15:44:39 +03:00
CrazyMax and GitHub
43c1071c5c
Merge pull request #3945 from docker/dependabot/github_actions/codeql-actions-ac07fb48a3
...
build(deps): bump the codeql-actions group with 4 updates
2026-07-08 09:22:41 +02:00
Tõnis Tiigi and GitHub
a21f0a4ffb
Merge pull request #3933 from amarkdotdev/fix/imagetools-create-descriptor-validation
...
imagetools: validate descriptor input for create -f
2026-07-07 14:23:05 -07:00
dependabot[bot] and GitHub
8d6cdb5762
build(deps): bump the codeql-actions group with 4 updates
...
Bumps the codeql-actions group with 4 updates: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ), [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ) and [github/codeql-action/analyze](https://github.com/github/codeql-action ).
Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
Updates `github/codeql-action/init` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
Updates `github/codeql-action/autobuild` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
Updates `github/codeql-action/analyze` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-07 21:15:18 +00:00
Tõnis Tiigi and GitHub
d77ee9536e
Merge pull request #3942 from crazy-max/group-codeql
...
chore: group codeql dependabot updates
2026-07-07 14:09:04 -07:00
CrazyMax
c64aa31cc7
chore: group codeql dependabot updates
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-07-07 08:26:42 +02:00
CrazyMax and GitHub
041dcec566
Merge pull request #3941 from docker/dependabot/github_actions/docker/setup-buildx-action-4.2.0
...
build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
2026-07-07 08:12:11 +02:00
CrazyMax and GitHub
ea4b0f0c21
Merge pull request #3936 from docker/dependabot/github_actions/docker/login-action-4.4.0
...
build(deps): bump docker/login-action from 4.2.0 to 4.4.0
2026-07-07 08:11:49 +02:00
amarkdotdev
ff1f2cbff6
imagetools: unmarshal descriptor JSON once in parseSource
...
Parse schemaVersion and descriptor fields in a single pass instead of
calling json.Unmarshal twice.
Signed-off-by: amarkdotdev <amarkdotdev@users.noreply.github.com >
2026-07-07 07:23:59 +03:00
Tonis Tiigi
03479f1a96
policy: allow array.flatten and template strings
...
Enable new builtins from OPA v1.14. The template_strings parser
feature was already active via ast.Features, but evaluating the
$"..." syntax also requires the internal.template_string builtin
to be present in the capabilities allowlist.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2026-07-06 16:53:49 -07:00
Tõnis Tiigi and GitHub
80b990a339
Merge pull request #3934 from crazy-max/fix-rm-broken-builders
...
rm: handle broken builders during removal
2026-07-06 16:29:24 -07:00
amarkdotdev
89ec9fe9b3
imagetools: validate descriptor input for create -f
...
Return a clear error when -f contains a manifest or index instead of an OCI
content descriptor, and reject descriptors missing a valid digest. Avoids
a nil-pointer panic when piping inspect --raw output into imagetools create.
Fixes #2091
Signed-off-by: amarkdotdev <amarkdotdev@users.noreply.github.com >
2026-07-06 23:23:25 +03:00
dependabot[bot] and GitHub
a7dcfec891
build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-06 18:39:02 +00:00
dependabot[bot] and GitHub
2bf0884e32
build(deps): bump docker/login-action from 4.2.0 to 4.4.0
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 4.2.0 to 4.4.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...af1e73f918a031802d376d3c8bbc3fe56130a9b0 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-06 18:33:27 +00:00
CrazyMax
8db022122d
rm: clean up all nodes before returning errors
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-07-06 12:14:11 +02:00
CrazyMax
4f6f49dd81
rm: allow removing builders with invalid config
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com >
2026-07-06 12:04:37 +02:00
CrazyMax and GitHub
cd58eac2cb
Merge pull request #3932 from docker/dependabot/github_actions/docker/bake-action/subaction/matrix-7.3.0
...
build(deps): bump docker/bake-action/subaction/matrix from 7.2.0 to 7.3.0
2026-07-06 10:21:10 +02:00
CrazyMax and GitHub
33acfebf16
Merge pull request #3931 from docker/dependabot/github_actions/docker/bake-action-7.3.0
...
build(deps): bump docker/bake-action from 7.2.0 to 7.3.0
2026-07-06 10:20:46 +02:00
CrazyMax and GitHub
ce1e9b7bd7
Merge pull request #3930 from docker/dependabot/github_actions/docker/setup-qemu-action-4.2.0
...
build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0
2026-07-06 10:20:21 +02:00
dependabot[bot] and GitHub
898b0c2337
build(deps): bump docker/bake-action/subaction/matrix
...
Bumps [docker/bake-action/subaction/matrix](https://github.com/docker/bake-action ) from 7.2.0 to 7.3.0.
- [Release notes](https://github.com/docker/bake-action/releases )
- [Commits](https://github.com/docker/bake-action/compare/6614cfa25eff9a0b2b2697efb0b6159e7680d584...d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b )
---
updated-dependencies:
- dependency-name: docker/bake-action/subaction/matrix
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-03 18:35:33 +00:00
dependabot[bot] and GitHub
8717083bc3
build(deps): bump docker/bake-action from 7.2.0 to 7.3.0
...
Bumps [docker/bake-action](https://github.com/docker/bake-action ) from 7.2.0 to 7.3.0.
- [Release notes](https://github.com/docker/bake-action/releases )
- [Commits](https://github.com/docker/bake-action/compare/6614cfa25eff9a0b2b2697efb0b6159e7680d584...d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b )
---
updated-dependencies:
- dependency-name: docker/bake-action
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-03 18:35:24 +00:00
dependabot[bot] and GitHub
b4ebd91998
build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-03 18:32:51 +00:00
CrazyMax and GitHub
dc8fa3045b
Merge pull request #3918 from s3onghyun/fix-bakeenvfiles-param
...
bake: fix duplicated type in bakeEnvFiles lookup param
2026-07-02 15:05:53 +02:00
CrazyMax and GitHub
91659f60b8
Merge pull request #3929 from glours/bump-compose-go-v2.13.0
...
bump compose-go to version v2.13.0
2026-07-02 12:24:20 +02:00
Guillaume Lours
0492548633
bump compose-go to version v2.13.0
...
Signed-off-by: Guillaume Lours <705411+glours@users.noreply.github.com >
2026-07-02 11:46:15 +02:00
Sebastiaan van Stijn
c74f522b8e
vendor: github.com/open-policy-agent/opa v1.14.1
...
updating to the lowest minor release that contains [opa@e9ca3ed], which removed
some redundant imports that resulted in indirect dependencies.
full diff: https://github.com/open-policy-agent/opa/compare/v1.10.1...v1.14.1
[opa@e9ca3ed]: https://github.com/open-policy-agent/opa/commit/e9ca3ed4151e5f1850b379aa62cad77669f453a5
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:34 +02:00
Sebastiaan van Stijn
3bcb873b04
vendor: github.com/vektah/gqlparser/v2 v2.5.32
...
- Add formatter.WithNonIntrospectionBuiltin
- Add a nil check in ArgumentMap
- fix(validator): allow nullable variables for nonnull args with default
- lint and format
full diff: https://github.com/vektah/gqlparser/compare/v2.5.30...v2.5.32
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:34 +02:00
Sebastiaan van Stijn
1adcd07066
vendor: github.com/lestrrat-go/jwx/v3 v3.0.13
...
full diff: https://github.com/lestrrat-go/jwx/compare/v3.0.11...v3.0.13
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:34 +02:00
Sebastiaan van Stijn
4b595a3671
vendor: github.com/lestrrat-go/httprc/v3 v3.0.2
...
full diff: https://github.com/lestrrat-go/httprc/compare/v3.0.1...v3.0.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:33 +02:00
Sebastiaan van Stijn
3f0b52dc73
vendor: github.com/valyala/fastjson v1.6.7
...
- pool.go: add missing Arena.Reset() call inside ArenaPool.Put()
- Treat nil values as null in SetArrayItem
prevents a potential panic when a nil value is used as an array item
full diff: https://github.com/valyala/fastjson/compare/v1.6.4...v1.6.7
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:33 +02:00
Sebastiaan van Stijn
0ff357e4be
vendor: github.com/segmentio/asm v1.2.1
...
- LICENSE CHANGE: MIT to MIT-0 (No Attribution)
- replace arm64 macro to please go vet
full diff: https://github.com/segmentio/asm/compare/v1.2.0...v1.2.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 15:31:33 +02:00
CrazyMax and GitHub
9587b741bc
Merge pull request #3912 from thaJeztah/bump_moby
...
vendor: github.com/docker/cli v29.6.1
2026-07-01 15:15:02 +02:00
CrazyMax and GitHub
490fe96c24
Merge pull request #3920 from thaJeztah/bump_containerd
...
vendor: github.com/containerd/containerd/v2 v2.2.5
2026-07-01 15:14:20 +02:00
Sebastiaan van Stijn
d27d845f75
vendor: github.com/docker/cli v29.6.1
...
full diff: https://github.com/docker/cli/compare/v29.5.3...v29.6.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-01 14:43:19 +02:00
CrazyMax and GitHub
5f67f9bcee
Merge pull request #3927 from docker/dependabot/github_actions/actions/setup-go-6.5.0
...
build(deps): bump actions/setup-go from 6.4.0 to 6.5.0
2026-06-29 11:37:57 +02:00
CrazyMax and GitHub
acc081ba1f
Merge pull request #3922 from docker/dependabot/github_actions/softprops/action-gh-release-3.0.1
...
build(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1
2026-06-29 11:37:34 +02:00
CrazyMax and GitHub
9079f2d091
Merge pull request #3921 from docker/dependabot/github_actions/actions/checkout-7.0.0
...
build(deps): bump actions/checkout from 6.0.3 to 7.0.0
2026-06-29 11:37:14 +02:00
CrazyMax and GitHub
eae76a9b4d
Merge pull request #3926 from docker/dependabot/github_actions/crazy-max-dot-github-8c77e18ee6
...
build(deps): bump the crazy-max-dot-github group across 1 directory with 5 updates
2026-06-29 11:36:47 +02:00
MohammadHasan Akbari
d3d1828d84
remote: use endpoint address for buildkit client authority
...
The remote driver created the buildkit client with an empty address:
client.New(ctx, "", opts...)
With an empty address the buildkit client falls back to the system
default address (the local unix socket) and derives the gRPC
":authority" pseudo-header from it, which ends up being "localhost".
The actual connection was still correct because the remote driver
provides its own dialer, but the wrong authority broke HTTP/2 reverse
proxies (such as Envoy) that route based on ":authority".
Pass the configured endpoint address to client.New so the authority is
derived from the remote endpoint hostname (e.g.
my-buildkit.example.com:443). The custom dialer is preserved, so the
dial target and TLS/SNI behavior are unchanged.
Fixes #3880
Signed-off-by: MohammadHasan Akbari <jarqvi.jarqvi@gmail.com >
2026-06-28 15:24:28 +04:00
dependabot[bot] and GitHub
2e96ce7b8b
build(deps): bump actions/setup-go from 6.4.0 to 6.5.0
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 6.4.0 to 6.5.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 6.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-25 18:36:25 +00:00
dependabot[bot] and GitHub
7b7b1ab58f
build(deps): bump the crazy-max-dot-github group across 1 directory with 5 updates
...
Bumps the crazy-max-dot-github group with 5 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [crazy-max/.github/.github/actions/gotest-annotations](https://github.com/crazy-max/.github ) | `1.10.0` | `1.10.1` |
| [crazy-max/.github/.github/actions/docker-scout](https://github.com/crazy-max/.github ) | `1.10.0` | `1.10.1` |
| [crazy-max/.github/.github/actions/install-k3s](https://github.com/crazy-max/.github ) | `1.10.0` | `1.10.1` |
| [crazy-max/.github/.github/workflows/pr-assign-author.yml](https://github.com/crazy-max/.github ) | `1.10.0` | `1.10.1` |
| [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github ) | `1.10.0` | `1.10.1` |
Updates `crazy-max/.github/.github/actions/gotest-annotations` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
Updates `crazy-max/.github/.github/actions/docker-scout` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
Updates `crazy-max/.github/.github/actions/install-k3s` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
Updates `crazy-max/.github/.github/workflows/pr-assign-author.yml` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
Updates `crazy-max/.github/.github/workflows/zizmor.yml` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/actions/gotest-annotations
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/actions/docker-scout
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/actions/install-k3s
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/pr-assign-author.yml
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-25 18:32:55 +00:00
Sebastiaan van Stijn
e1e5963dae
vendor: github.com/containerd/containerd/v2 v2.2.5
...
- full diff: https://github.com/containerd/containerd/compare/v2.2.4...v2.2.5
- release notes: https://github.com/containerd/containerd/releases/tag/v2.2.5
The fifth patch release for containerd 2.2 contains various fixes
and updates including security patches.
- CVE-2026-50195 / [GHSA-cvxm-645q-p574] CRI: checkpoint import allows local image tag poisoning
- CVE-2026-53488 / [GHSA-xhf5-7wjv-pqxp] CRI: image-config LABEL flows to host-root command execution from an image pull
- CVE-2026-53492 / [GHSA-33vj-92qq-66hc] CRI: CDI annotation smuggling during CRI checkpoint restore
- CVE-2026-53489 / [GHSA-rgh6-rfwx-v388] CRI: Arbitrary host file read via symlink following in CRI checkpoint restore
- CVE-2026-47262 / [GHSA-jpcc-p29g-p8mq] containerd image-triggered runtime DoS via unbounded group parsing
[GHSA-cvxm-645q-p574]: https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574
[GHSA-xhf5-7wjv-pqxp]: https://github.com/containerd/containerd/security/advisories/GHSA-xhf5-7wjv-pqxp
[GHSA-33vj-92qq-66hc]: https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc
[GHSA-rgh6-rfwx-v388]: https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388
[GHSA-jpcc-p29g-p8mq]: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-23 09:27:04 +02:00