dependabot[bot] opened a new pull request, #551:
URL: https://github.com/apache/dubbo-go-pixiu/pull/551

   Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 
0.10.1 to 0.11.4.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/moby/buildkit/releases";>github.com/moby/buildkit's 
releases</a>.</em></p>
   <blockquote>
   <h2>v0.11.4</h2>
   <p><a 
href="https://hub.docker.com/r/moby/buildkit";>https://hub.docker.com/r/moby/buildkit</a></p>
   <h3>Notable changes:</h3>
   <h4>This release contains two security fixes.</h4>
   <ul>
   <li>
   <p>Fix the issue where credentials inlined to Git URLs could end up in 
provenance attestation <a 
href="https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc";>https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc</a></p>
   </li>
   <li>
   <p>Containerd has been updated to 1.6.18 , fixing issue with supplementary 
groups not being set up properly <a 
href="https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p";>https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p</a>
 <a href="https://redirect.github.com/moby/buildkit/issues/3651";>#3651</a></p>
   </li>
   </ul>
   <h4>Other updates</h4>
   <ul>
   <li>Fix possible panic with writing annotations <a 
href="https://redirect.github.com/moby/buildkit/issues/3670";>#3670</a></li>
   <li>Fix possible panic with passing nil frontend input <a 
href="https://redirect.github.com/moby/buildkit/issues/3659";>#3659</a></li>
   <li>Fix file capabilities in merged snapshots by changing chown order <a 
href="https://redirect.github.com/moby/buildkit/issues/3671";>#3671</a></li>
   </ul>
   <h2>v0.11.3</h2>
   <p>Welcome to the 0.11.3 release of buildkit!</p>
   <p>Please try out the release binaries and report any issues at
   <a 
href="https://github.com/moby/buildkit/issues";>https://github.com/moby/buildkit/issues</a>.</p>
   <h3>Notable Changes</h3>
   <ul>
   <li>Builtin Dockerfile frontend updated to v1.5.2</li>
   <li>Fix not mounting optional secrets missing from build requests <a 
href="https://redirect.github.com/moby/buildkit/issues/3561";>#3561</a></li>
   <li>Fix an issue with Github cache backend that could cause invalid range 
requests <a 
href="https://redirect.github.com/moby/buildkit/issues/3618";>#3618</a></li>
   <li>Fix possible cache loading error when loading local cache created by 
BuildKit releases older than v0.10 <a 
href="https://redirect.github.com/moby/buildkit/issues/3605";>#3605</a></li>
   <li>Fix issues with missing layer metadata in SBOMs in latest releases <a 
href="https://redirect.github.com/moby/buildkit/issues/3594";>#3594</a></li>
   <li>Fix possible &quot;digest not found&quot; error on exporting build 
results <a 
href="https://redirect.github.com/moby/buildkit/issues/3566";>#3566</a></li>
   <li>Make sure timezones are dropped on handling 
<code>SOURCE_DATE_EPOCH</code> <a 
href="https://redirect.github.com/moby/buildkit/issues/3559";>#3559</a></li>
   </ul>
   <h3>Dependency Changes</h3>
   <ul>
   <li><strong>github.com/containerd/containerd</strong>  1709cfe273d9 -&gt; 
v1.6.16</li>
   </ul>
   <p>Previous release can be found at <a 
href="https://github.com/moby/buildkit/releases/tag/v0.11.2";>v0.11.2</a></p>
   <h2>v0.11.2</h2>
   <p>Welcome to the 0.11.2 release of buildkit!</p>
   <p>Please try out the release binaries and report any issues at
   <a 
href="https://github.com/moby/buildkit/issues";>https://github.com/moby/buildkit/issues</a>.</p>
   <h3>Notable changes</h3>
   <ul>
   <li>Update containerd patches to fix regression in handling push errors <a 
href="https://redirect.github.com/moby/buildkit/issues/3531";>#3531</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/moby/buildkit/commit/3abd1ef0c195cdc078d1657cb50f62a2cdc26f8f";><code>3abd1ef</code></a>
 Merge pull request from GHSA-gc89-7gcr-jxqc</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/7d45f9904bbe151dc6583b84cc0f4e25e0b1d5e0";><code>7d45f99</code></a>
 provenance: ensure URLs are redacted before written</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/218e934edfbaabf5e2153cc76c786fdc2d68c4b1";><code>218e934</code></a>
 Merge pull request <a 
href="https://redirect.github.com/moby/buildkit/issues/3676";>#3676</a> from 
vvoland/sbomsupplements-hang-011</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/e344f3a4f6d9c77397cb998248d93c989bf86928";><code>e344f3a</code></a>
 test/client: Close buildkit client</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/0df0faaf2223c403db33b0fb6c4f6a62939379f2";><code>0df0faa</code></a>
 Merge pull request <a 
href="https://redirect.github.com/moby/buildkit/issues/3614";>#3614</a> from 
crazy-max/v0.11_deprecate-buildinfo</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/2590f953a054349cf31e3a665a7ab2d6182dcad3";><code>2590f95</code></a>
 Merge pull request <a 
href="https://redirect.github.com/moby/buildkit/issues/3673";>#3673</a> from 
tonistiigi/v0.11.4-picks</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/97b37f98ac1b627d6e866a5eb55b00d145280bd8";><code>97b37f9</code></a>
 diffapply: do chown before xattrs</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/17401b5b7207a2c816fac11ebde385764d728c66";><code>17401b5</code></a>
 Fix buildkitd panic when frontend input is nil.</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/99aaa105b2322922c567b983aa22c03ccea12b5b";><code>99aaa10</code></a>
 fix a possible panic on cache</li>
   <li><a 
href="https://github.com/moby/buildkit/commit/837b4b21634326ec8b672a3300ea23c746341fd4";><code>837b4b2</code></a>
 buildinfo: add BUILDKIT_BUILDINFO build arg</li>
   <li>Additional commits viewable in <a 
href="https://github.com/moby/buildkit/compare/v0.10.1...v0.11.4";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/moby/buildkit&package-manager=go_modules&previous-version=0.10.1&new-version=0.11.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/dubbo-go-pixiu/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to