Skip to content

Releases: moby/buildkit

v0.34.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 23:37
v0.34.0
f5b59a1

buildkit 0.34.0

Welcome to the v0.34.0 release of buildkit!

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Ernestas Lukoševičius
  • Alexandre Rodrigues
  • Kamil Monicz
  • okhowang(王沛文)
  • Alex G. Wolff
  • Ben Harris
  • Guthrie McAfee Armstrong
  • Jonathan A. Sternberg
  • KR Ravindra
  • MohammadHasan Akbari
  • MsfPablo
  • Paul Schroeder
  • Ruzan Sasuri
  • Sterling Greene
  • Suhail Hany
  • ZRHann

Notable changes

  • Built-in Dockerfile frontend has been updated to v1.28.0 changelog
  • BoltDB databases now support compaction to periodically reduce database size and compress them on disk. This feature is currently opt-in and can be enabled with TOML configuration. The intention is to enable it by default in future releases. #7138 #7248
  • Local and tar exporters now support the src option for specifying the subdirectory to export. #7226
  • Provenance attestation now contains information about the target platform of the build. #7227
  • Unpack exporter option is not supported in rewrite-timestamp mode. #6939
  • Reduce BoltDB database size and performance overhead #6882
  • Transient registry token failures are now retried. #7155
  • Add protection to using concurrent local cache exports with reset option. #7153
  • NewContainer API in Gateway now preserves the platform information of the created container. #7083
  • Enable configuring Hyper-V isolation mode for Windows containers. #7067
  • S3 remote cache backend now supports compression options. #7121
  • Session authentication timeout is now configurable from TOML configuration. #7225
  • Startup performance of internal databases has been improved by creating a BoltDB freelist on graceful shutdown #7249
  • Improve recovery from database open failures in more internal databases. #7137
  • Buildkitd now supports defining the configuration path with an environment variable. #7144
  • Original messages from GitHub cache backend are now preserved. #7232
  • Avoid panic from misconfigured GC policy. #7209
  • Fix issue where some cache records could remain in use after build completion with an error. #7223
  • Fix possible cache export failure with parallel requests. #7145
  • Fix incorrect backslash escaping in RUN step progress output. #7188
  • Fix encoding of some material URLs with custom ports in the provenance attestation. #5641
  • Fix possible "ref locked: unavailable" errors on parallel builds export step. #7182
  • Fix possible build errors when using SOURCE_DATE_EPOCH together with subdir Git sources. #7183
  • Fix possible EBUSY errors from overlay filesystem on some systems. #7167
  • Fix bug that could cause some internal database indexes to never get released. #7135
  • Fix handling of IPv6 hosts without an explicit port. #7164
  • Fix possible build error when canceling QEMU emulated build step. #7092
  • Fix using normalized variant of platform identifier in annotation key #7244
  • Fix possible storage reference leak when canceling build in the middle of exec step #7247
  • Fix possible deadlock on large bidirectional stdio streams #7240
  • Fix possible hang on container output writer error #7243

Dependency Changes

  • github.com/aws/aws-sdk-go-v2 v1.43.8 -> v1.47.0
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.18 -> v1.7.20
  • github.com/aws/aws-sdk-go-v2/config v1.32.39 -> v1.33.4
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.38 -> v1.20.4
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.39 -> v1.20.0
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.39 -> v1.5.3
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.39 -> v2.8.3
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.40 -> v1.5.3
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.18 -> v1.13.19
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.39 -> v1.14.3
  • github.com/aws/aws-sdk-go-v2/service/signin v1.5.8 -> v1.10.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.33.8 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.8 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.45.8 -> v1.50.0
  • github.com/aws/smithy-go v1.27.10 -> v1.28.2
  • github.com/containerd/containerd/api v1.11.1 -> v1.12.0
  • github.com/containerd/containerd/v2 v2.3.6 -> v2.4.1
  • github.com/containerd/go-cni v1.1.13 -> v1.1.14
  • github.com/containerd/log/otel v0.1.0 new
  • github.com/containerd/ttrpc v1.2.9 -> v1.2.10
  • github.com/containernetworking/cni v1.3.0 -> v1.3.1
  • github.com/cyphar/filepath-securejoin v0.6.1 -> v0.7.0
  • github.com/docker/cli v29.7.2 -> v29.8.2
  • github.com/docker/docker-credential-helpers v0.9.8 -> v0.9.9
  • github.com/docker/go-metrics v0.0.1 -> v0.1.0
  • github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
  • github.com/go-openapi/analysis v0.25.2 -> v0.25.5
  • github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
  • github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
  • github.com/go-openapi/loads v0.24.0 -> v0.25.0
  • github.com/go-openapi/runtime v0.32.4 -> v0.33.0
  • github.com/go-openapi/spec v0.22.6 -> v0.22.9
  • github.com/go-openapi/strfmt v0.26.4 -> v0.27.0
  • github.com/go-openapi/swag v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/conv v0.27.0 -> v0.28.0
  • github.com/go-openapi/swag/fileutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/loading v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/mangling v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/netutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/pools v0.28.0 new
  • github.com/go-openapi/swag/stringutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/typeutils v0.27.0 -> v0.28.0
  • github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/validate v0.26.0 -> v0.26.1
  • github.com/gofrs/flock v0.13.0 -> v0.13.1
  • github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 -> v2.30.0
  • github.com/klauspost/compress v1.19.2 -> v1.20.1
  • github.com/moby/policy-helpers dd6c5499c491 -> bd98f4747414
  • github.com/moby/profiles/seccomp v0.2.3 -> v0.2.4
  • github.com/moby/sys/userns v0.2.0 -> v0.2.1
  • github.com/package-url/packageurl-go v0.1.1 -> v0.1.7
  • github.com/prometheus/client_model v0.6.2 -> v0.6.3
  • github.com/prometheus/common v0.70.1 -> v0.71.0
  • github.com/sirupsen/logrus v1.10.1 -> v1.10.2
  • github.com/tonistiigi/go-actions-cache 54bc28c26fd2 -> afe8013b5ac4
  • github.com/urfave/cli/v3 v3.9.0 -> v3.11.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.70.0 -> v0.71.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.70.0 -> v0.71.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0 -> v0.71.0
  • go.opentelemetry.io/otel v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp ...
Read more

dockerfile/1.28.0-labs

Choose a tag to compare

@github-actions github-actions released this 07 Oct 23:38
f5b59a1

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.28.0-labs

dockerfile/1.28.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 23:37
f5b59a1

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.28.0

Notable changes

  • Allow "default group" syntax in COPY --chown instruction. #3555
  • Add better detection for invalid combinations between --chown and --link in the COPY instruction. #7134

v0.34.0-rc2

v0.34.0-rc2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 06 Oct 23:31
v0.34.0-rc2
6fca433

buildkit 0.34.0-rc2

Welcome to the v0.34.0-rc2 release of buildkit!
This is a pre-release of buildkit

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn
  • Kamil Monicz
  • Ruzan Sasuri

Notable Changes

  • Startup performance of internal databases has been improved by creating a BoltDB freelist on graceful shutdown #7249
  • Database compaction now supports configuring minimum reclaimable percentage to avoid unnecessary compaction on very big databases #7248
  • Fix using normalized variant of platform identifier in annotation key #7244
  • Fix possible storage reference leak when canceling build in the middle of exec step #7247
  • Fix possible deadlock on large bidirectional stdio streams #7240
  • Fix possible hang on container output writer error #7243

Dependency Changes

  • github.com/docker/cli v29.8.1 -> v29.8.2
  • github.com/moby/policy-helpers 72f704e6cdb6 -> bd98f4747414

Previous release can be found at v0.34.0-rc1

dockerfile/1.28.0-rc2

dockerfile/1.28.0-rc2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 06 Oct 23:31
6fca433

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.28.0-rc2

dockerfile/1.28.0-rc1-labs

Pre-release

Choose a tag to compare

@github-actions github-actions released this 01 Oct 07:27
67aca42

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.28.0-rc1-labs

v0.34.0-rc1

v0.34.0-rc1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 01 Oct 01:20
v0.34.0-rc1
67aca42

buildkit 0.34.0-rc1

Welcome to the v0.34.0-rc1 release of buildkit!
This is a pre-release of buildkit

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn
  • Akihiro Suda
  • Ernestas Lukoševičius
  • Alexandre Rodrigues
  • okhowang(王沛文)
  • Alex G. Wolff
  • Ben Harris
  • Guthrie McAfee Armstrong
  • Jonathan A. Sternberg
  • KR Ravindra
  • MohammadHasan Akbari
  • MsfPablo
  • Paul Schroeder
  • Sterling Greene
  • Suhail Hany
  • ZRHann

Notable changes

  • Built-in Dockerfile frontend has been updated to v1.28.0-rc1 changelog
  • BoltDB databases now support compaction to periodically reduce database size and compress them on disk. This feature is currently opt-in and can be enabled with TOML configuration. The intention is to enable it by default in future releases. #7138
  • Local and tar exporters now support the src option for specifying the subdirectory to export. #7226
  • Provenance attestation now contains information about the target platform of the build. #7227
  • Unpack exporter option is not supported in rewrite-timestamp mode. #6939
  • Reduce BoltDB database size and performance overhead #6882
  • Transient registry token failures are now retried. #7155
  • Add protection to using concurrent local cache exports with reset option. #7153
  • NewContainer API in Gateway now preserves the platform information of the created container. #7083
  • Enable configuring Hyper-V isolation mode for Windows containers. #7067
  • S3 remote cache backend now supports compression options. #7121
  • Session authentication timeout is now configurable from TOML configuration. #7225
  • Improve recovery from database open failures in more internal databases. #7137
  • Buildkitd now supports defining the configuration path with an environment variable. #7144
  • Original messages from GitHub cache backend are now preserved. #7232
  • Avoid panic from misconfigured GC policy. #7209
  • Fix issue where some cache records could remain in use after build completion with an error. #7223
  • Fix possible cache export failure with parallel requests. #7145
  • Fix incorrect backslash escaping in RUN step progress output. #7188
  • Fix encoding of some material URLs with custom ports in the provenance attestation. #5641
  • Fix possible "ref locked: unavailable" errors on parallel builds export step. #7182
  • Fix possible build errors when using SOURCE_DATE_EPOCH together with subdir Git sources. #7183
  • Fix possible EBUSY errors from overlay filesystem on some systems. #7167
  • Fix bug that could cause some internal database indexes to never get released. #7135
  • Fix handling of IPv6 hosts without an explicit port. #7164
  • Fix possible build error when canceling QEMU emulated build step. #7092

Dependency Changes

  • github.com/aws/aws-sdk-go-v2 v1.43.8 -> v1.47.0
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.18 -> v1.7.20
  • github.com/aws/aws-sdk-go-v2/config v1.32.39 -> v1.33.4
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.38 -> v1.20.4
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.39 -> v1.20.0
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.39 -> v1.5.3
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.39 -> v2.8.3
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.40 -> v1.5.3
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.18 -> v1.13.19
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.39 -> v1.14.3
  • github.com/aws/aws-sdk-go-v2/service/signin v1.5.8 -> v1.10.0
  • github.com/aws/aws-sdk-go-v2/service/sso v1.33.8 -> v1.38.0
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.8 -> v1.43.0
  • github.com/aws/aws-sdk-go-v2/service/sts v1.45.8 -> v1.50.0
  • github.com/aws/smithy-go v1.27.10 -> v1.28.2
  • github.com/containerd/containerd/api v1.11.1 -> v1.12.0
  • github.com/containerd/containerd/v2 v2.3.6 -> v2.4.1
  • github.com/containerd/go-cni v1.1.13 -> v1.1.14
  • github.com/containerd/log/otel v0.1.0 new
  • github.com/containerd/ttrpc v1.2.9 -> v1.2.10
  • github.com/containernetworking/cni v1.3.0 -> v1.3.1
  • github.com/cyphar/filepath-securejoin v0.6.1 -> v0.7.0
  • github.com/docker/cli v29.7.2 -> v29.8.1
  • github.com/docker/docker-credential-helpers v0.9.8 -> v0.9.9
  • github.com/docker/go-metrics v0.0.1 -> v0.1.0
  • github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
  • github.com/go-openapi/analysis v0.25.2 -> v0.25.5
  • github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
  • github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
  • github.com/go-openapi/loads v0.24.0 -> v0.25.0
  • github.com/go-openapi/runtime v0.32.4 -> v0.33.0
  • github.com/go-openapi/spec v0.22.6 -> v0.22.9
  • github.com/go-openapi/strfmt v0.26.4 -> v0.27.0
  • github.com/go-openapi/swag v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/conv v0.27.0 -> v0.28.0
  • github.com/go-openapi/swag/fileutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/loading v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/mangling v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/netutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/pools v0.28.0 new
  • github.com/go-openapi/swag/stringutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/swag/typeutils v0.27.0 -> v0.28.0
  • github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.28.0
  • github.com/go-openapi/validate v0.26.0 -> v0.26.1
  • github.com/gofrs/flock v0.13.0 -> v0.13.1
  • github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 -> v2.30.0
  • github.com/klauspost/compress v1.19.2 -> v1.20.1
  • github.com/moby/policy-helpers dd6c5499c491 -> 72f704e6cdb6
  • github.com/moby/profiles/seccomp v0.2.3 -> v0.2.4
  • github.com/moby/sys/userns v0.2.0 -> v0.2.1
  • github.com/package-url/packageurl-go v0.1.1 -> v0.1.7
  • github.com/prometheus/client_model v0.6.2 -> v0.6.3
  • github.com/prometheus/common v0.70.1 -> v0.71.0
  • github.com/sirupsen/logrus v1.10.1 -> v1.10.2
  • github.com/tonistiigi/go-actions-cache 54bc28c26fd2 -> afe8013b5ac4
  • github.com/urfave/cli/v3 v3.9.0 -> v3.11.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.70.0 -> v0.71.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.70.0 -> v0.71.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0 -> v0.71.0
  • go.opentelemetry.io/otel v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0 -> v1.46.0
  • go.opentelemetry.io/otel/exporters/prometheus ...
Read more

v0.33.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 17:08
v0.33.1
8c91502

Welcome to the v0.33.1 release of buildkit!

Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn

Notable Changes

  • Built-in Dockerfile frontend has been updated to v1.27.1 changelog.
  • Fix proxy CA cleanup so build steps cannot redirect it outside the build rootfs, block it with a special file, or succeed when cleanup fails. GHSA-2f5p-x9ph-g97x
  • Fix a daemon panic when a build requests CDI devices while CDI support is disabled. Optional devices are ignored; required devices produce an error. GHSA-r456-g3gm-cvxf
  • Verify container blob contents against their claimed digest before caching them. This protects shared caches from unverified blobs supplied through the low-level LLB API. GHSA-p3rc-w3hc-pqvv
  • Verify applied image layer DiffIDs, bind lazy stargz snapshots to their verified TOC digest, and isolate legacy layer snapshots. Image source cache keys no longer rely on unverified DiffIDs. GHSA-f2v9-hprr-32q3
  • Prevent malicious external frontends from crashing the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
  • Reject special files in daemon-side snapshot reads and replace existing special files safely in LLB mkfile operations. GHSA-9728-qjrv-2xh2
  • Reject malformed LLB file operations with invalid symlink owner inputs instead of allowing a daemon panic. GHSA-fjj4-h6vf-m9hj
  • Reject malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic. GHSA-cv6p-7w7g-xjwq
  • Limit Dockerfile, .dockerignore, gateway file, and nested LLB definition reads to prevent oversized inputs from exhausting daemon memory. GHSA-mgqf-486f-49vp
  • Apply source policies to Git bundle locators and reject Git full remote URLs that do not match the source identifier. GHSA-66hf-6vf5-87hc

Dependency Changes

  • github.com/containerd/containerd/v2 v2.3.4 -> v2.3.6
  • golang.org/x/crypto v0.55.0 -> v0.56.0

Previous release can be found at v0.33.0

dockerfile/1.27.1-labs

Choose a tag to compare

@github-actions github-actions released this 30 Sep 17:07
dockerfile/1.27.1-labs
08f4630

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.27.1-labs

dockerfile/1.27.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 17:07
dockerfile/1.27.1
08f4630

Usage

# syntax=docker.io/docker/dockerfile-upstream:1.27.1

Notable changes

  • Reject Dockerfiles and .dockerignore files larger than 16 MiB instead of loading them without a limit. GHSA-mgqf-486f-49vp
  • Limit reads of HTTP archives to 16 MiB when inspecting them for SOURCE_DATE_EPOCH timestamps. GHSA-mgqf-486f-49vp