Skip to content

build(deps): bump github.com/moby/buildkit from 0.24.0 to 0.28.1 in /tools/get-deps#5703

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/tools/get-deps/github.com/moby/buildkit-0.28.1
Open

build(deps): bump github.com/moby/buildkit from 0.24.0 to 0.28.1 in /tools/get-deps#5703
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/tools/get-deps/github.com/moby/buildkit-0.28.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 26, 2026

Bumps github.com/moby/buildkit from 0.24.0 to 0.28.1.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.28.1

Welcome to the v0.28.1 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn

Notable Changes

  • Fix insufficient validation of Git URL #ref:subdir fragments that could allow access to restricted files outside the checked-out repository root. GHSA-4vrq-3vrq-g6gg
  • Fix a vulnerability where an untrusted custom frontend could cause files to be written outside the BuildKit state directory. GHSA-4c29-8rgm-jvjj
  • Fix a panic when processing invalid .dockerignore patterns during COPY. #6610 moby/patternmatcher#9

Dependency Changes

  • github.com/moby/patternmatcher v0.6.0 -> v0.6.1

Previous release can be found at v0.28.0

v0.28.0

buildkit 0.28.0

Welcome to the v0.28.0 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn
  • Jonathan A. Sternberg
  • Akihiro Suda
  • Amr Mahdi
  • Dan Duvall
  • David Karlsson
  • Jonas Geiler
  • Kevin L.
  • rsteube

... (truncated)

Commits
  • 45b038c git: normalize and validate subdir paths
  • f5462c2 git: harden ref arg handling
  • 71577a5 source: extract SafeFileName into shared pathutil package
  • df43783 source/http: use os.Root for saved file operations
  • 9ce6f62 source/http: sanitize downloaded filenames
  • 099cf80 executor: validate container IDs centrally
  • 2642113 Merge pull request #6610 from thaJeztah/0.28_backport_bump_patternmatcher
  • 802da78 vendor: github.com/moby/patternmatcher v0.6.1
  • 5245d86 Merge pull request #6551 from tonistiigi/v0.28-cherry-picks
  • 90ee5de vendor: update x/net to v0.51.0
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Mar 26, 2026
@eriknordmark
Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/go_modules/tools/get-deps/github.com/moby/buildkit-0.28.1 branch from d9cbacd to 9843f1f Compare March 27, 2026 21:31
@eriknordmark
Copy link
Copy Markdown
Contributor

Current investigation for the buildkit/linuxkit compatibility build failure is:
Conclusion

There is no version of linuxkit — tagged or untagged, including master HEAD —
that is compatible with buildkit v0.28.1. Linuxkit's latest buildkit
dependency is v0.26.3, and the ConfigFile removal happened in v0.28.x.
Linuxkit simply hasn't adopted the new API yet.

The only viable path (without modifying vendor code) would be to revert the
buildkit dependency to v0.27.x or earlier until linuxkit catches up. Would you
like to explore pinning buildkit to an older version that still has the
ConfigFile field?

Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.24.0 to 0.28.1.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.24.0...v0.28.1)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.28.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/tools/get-deps/github.com/moby/buildkit-0.28.1 branch from 9843f1f to db897d7 Compare April 1, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant