Paweł Gronowski
f816d5c003
sync-release-branch: Run from master against selected release
...
The workflow previously inferred its target from the dispatch ref,
requiring operators to always sync the release branch with the
workflow/scripts on master.
Accept the release branch as an input, keep the dispatched master
checkout as the script source, and merge in a detached worktree at the
selected release revision.
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-07-10 13:49:45 +02:00
Paweł Gronowski and GitHub
25a1d41669
Merge pull request #7094 from thaJeztah/rm_go_reportcard
...
README: remove Go Report Card badge
2026-07-10 12:27:07 +02:00
Sebastiaan van Stijn and GitHub
ba55f0c3b1
Merge pull request #7096 from docker/dependabot/github_actions/docker-actions-c21f7ea42a
...
build(deps): bump the docker-actions group with 3 updates
2026-07-10 08:39:04 +02:00
Sebastiaan van Stijn and GitHub
9c1b7fc671
Merge pull request #7095 from docker/dependabot/github_actions/codeql-actions-920a780463
...
build(deps): bump the codeql-actions group with 3 updates
2026-07-10 08:37:26 +02:00
Sebastiaan van Stijn and GitHub
a8ddac1a8e
Merge pull request #7098 from vvoland/sync-editor
...
scripts/sync-branch: Fix non-interactive merge
2026-07-10 08:31:05 +02:00
Paweł Gronowski
f57e528457
scripts/sync-branch: Fix non-interactive merge
...
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-07-09 16:51:33 +02:00
Sebastiaan van Stijn and GitHub
9ba113bc5d
Merge pull request #7091 from vvoland/gha-sync-release
...
gha: Add release branch sync workflow
2026-07-09 14:29:42 +02:00
dependabot[bot] and GitHub
cd79c7ebfc
build(deps): bump the docker-actions group with 3 updates
...
Bumps the docker-actions group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ), [docker/login-action](https://github.com/docker/login-action ) and [docker/metadata-action](https://github.com/docker/metadata-action ).
Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c )
Updates `docker/login-action` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...c99871dec2022cc055c062a10cc1a1310835ceb4 )
Updates `docker/metadata-action` from 6.1.0 to 6.2.0
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](https://github.com/docker/metadata-action/compare/80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9...dc802804100637a589fabce1cb79ff13a1411302 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/login-action
dependency-version: 4.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/metadata-action
dependency-version: 6.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 08:47:18 +00:00
dependabot[bot] and GitHub
042528819a
build(deps): bump the codeql-actions group with 3 updates
...
Bumps the codeql-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ) and [github/codeql-action/analyze](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
Updates `github/codeql-action/autobuild` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
Updates `github/codeql-action/analyze` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: codeql-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 08:46:24 +00:00
Sebastiaan van Stijn
8c9e2f353e
README: remove Go Report Card badge
...
The project was sunset;
> After more than a decade of serving the ecosystem, the time
> has come to sunset Go Report Card. Following the loss of our
> primary infrastructure sponsor, maintaining the web app is
> no longer sustainable.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-09 01:03:31 +02:00
Sebastiaan van Stijn and GitHub
a86b9aa542
Merge pull request #7090 from docker/dependabot/go_modules/cmd/docker-trust/go_modules-a3c8a40308
...
build(deps): bump golang.org/x/crypto from 0.50.0 to 0.52.0 in /cmd/docker-trust in the go_modules group across 1 directory
2026-07-08 23:31:27 +02:00
Paweł Gronowski
182f56fe8c
gha: Add release branch sync workflow
...
Add a manually dispatched workflow for maintainers to sync a Docker
release branch to a selected release tag.
The sync-release-branch job checks out the release branch, computes
the list of unmerged tags up to the requested tag via
scripts/unmerged-tags, merges them in order via scripts/sync-branch
using git merge --no-ff (resolving conflicts by taking the tag's
content), then pushes the result to a temporary branch.
The push-release-branch job runs after manual approval via the
docker-releases environment. It verifies that neither the release
branch nor the temporary branch moved since the sync job ran before
force-advancing the release branch and deleting the temporary branch.
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-07-08 20:22:22 +02:00
Sebastiaan van Stijn and GitHub
e5c424fd70
Merge pull request #7092 from docker/dependabot/github_actions/docker-actions-78c0e55afe
...
build(deps): bump the docker-actions group with 2 updates
2026-07-08 15:00:29 +02:00
dependabot[bot] and GitHub
145e7f83cd
build(deps): bump the docker-actions group with 2 updates
...
Bumps the docker-actions group with 2 updates: [docker/bake-action](https://github.com/docker/bake-action ) and [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ).
Updates `docker/bake-action` from 7.2.0 to 7.3.0
- [Release notes](https://github.com/docker/bake-action/releases )
- [Commits](https://github.com/docker/bake-action/compare/6614cfa25eff9a0b2b2697efb0b6159e7680d584...d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b )
Updates `docker/setup-qemu-action` from 4.1.0 to 4.2.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8 )
---
updated-dependencies:
- dependency-name: docker/bake-action
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/setup-qemu-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-08 10:20:16 +00:00
Paweł Gronowski and GitHub
e8ded3fce7
Merge pull request #7085 from thaJeztah/dependabot_group
...
gha: dependabot: group docker/* and codeql action updates
2026-07-08 12:15:03 +02:00
dependabot[bot] and GitHub
91db63cf5b
build(deps): bump golang.org/x/crypto
...
Bumps the go_modules group with 1 update in the /cmd/docker-trust directory: [golang.org/x/crypto](https://github.com/golang/crypto ).
Updates `golang.org/x/crypto` from 0.50.0 to 0.52.0
- [Commits](https://github.com/golang/crypto/compare/v0.50.0...v0.52.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-version: 0.52.0
dependency-type: indirect
dependency-group: go_modules
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-08 09:15:41 +00:00
Paweł Gronowski and GitHub
d4218f26dc
Merge pull request #7087 from thaJeztah/update_go1.26.5
...
update to go1.26.5
2026-07-08 11:14:40 +02:00
Sebastiaan van Stijn
6d245daa91
update to go1.26.5
...
go1.26.5 (released 2026-07-07) includes security fixes to the crypto/tls
and os packages, as well as bug fixes to the compiler, the runtime, the
go command, and the net, os, and syscall packages. See the Go 1.26.5
milestone on our issue tracker for details;
- https://github.com/golang/go/issues?q=milestone%3AGo1.26.5+label%3ACherryPickApproved
- full diff: https://github.com/golang/go/compare/go1.26.4...go1.26.5
From the security announcement:
We have just released Go versions 1.26.5 and 1.25.12, minor point releases.
These releases include 2 security fixes following the security policy:
- os: Root escape via symlink plus trailing slash
On Unix systems, opening a file in an os.Root improperly
followed symlinks to locations outside of the Root when
the final path component of the a path is a symbolic link
and the path ends in /.
For example, root.Open("symlink/") would open "symlink"
even when "symlink" is a symbolic link pointing outside of the root.
On Unix, openat(fd, path, O_NOFOLLOW) will follow symlinks
in path when path ends in a /. Root failed to account for
this behavior, permitting paths with a trailing / to escape.
It now properly sanitizes the path parameter provided to openat.
hanks to Mundur for reporting this issue.
This is CVE-2026-39822 and Go issue https://go.dev/issue/79005 .
- crypto/tls: Encrypted Client Hello privacy leak
he Encrypted Client Hello implementation would leak the pre-shared key
dentities during the handshake, allowing a passive network observer who can
ollect handshakes to de-anonymize the hostname of the server, even when ECH was
eing used.
Thanks to Coia Prant (github.com/rbqvq) for reporting this issue.
This is CVE-2026-42505 and Go issue https://go.dev/issue/79282 .
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-08 00:01:42 +02:00
Sebastiaan van Stijn
2282b23f02
gha: dependabot: group docker/* and codeql action updates
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-07 15:56:25 +02:00
Sebastiaan van Stijn and GitHub
40a8e8e754
Merge pull request #7081 from vvoland/work-gha
...
Update docker-agent-action to v2.0.2
2026-07-06 11:43:13 +02:00
Paweł Gronowski
da2622ed8e
Update docker-agent-action to v2.0.2
...
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-07-06 11:35:08 +02:00
Sebastiaan van Stijn and GitHub
c4c704e62b
Merge pull request #7079 from derekmisler/fix/pr-review-trigger-concurrency
...
ci: add concurrency group to pr-review-trigger to prevent duplicate reviews
2026-07-02 16:40:57 +02:00
Derek Misler and Derek Misler
1c742902b6
ci: add concurrency group and remove bot filter in pr-review-trigger
...
Add a concurrency group keyed on PR number to prevent duplicate reviews
from simultaneous review_requested events.
Remove the sender.type != 'Bot' guard so Dependabot PRs remain
reviewable — per maintainer feedback, those reviews are useful for
catching behavior changes in dependency updates.
Signed-off-by: Derek Misler <derek.misler@docker.com >
2026-07-02 14:26:26 +00:00
Sebastiaan van Stijn and GitHub
0f83acece4
Merge pull request #7077 from docker/dependabot/github_actions/actions/setup-go-6.5.0
...
build(deps): bump actions/setup-go from 6.3.0 to 6.5.0
2026-06-30 20:40:27 +02:00
Paweł Gronowski and GitHub
3edebc433e
Merge pull request #7078 from thaJeztah/version
...
bump VERSION to v29.7.0-dev
2026-06-30 16:58:09 +02:00
Sebastiaan van Stijn
635fed89d2
bump VERSION to v29.7.0-dev
...
This reverts commit d9c59c9cfe .
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-30 16:31:14 +02:00
dependabot[bot] and GitHub
444bab12d9
build(deps): bump actions/setup-go from 6.3.0 to 6.5.0
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 6.3.0 to 6.5.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...924ae3a1cded613372ab5595356fb5720e22ba16 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 6.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-30 08:44:46 +00:00
Sebastiaan van Stijn and GitHub
8900f1d330
Merge pull request #7074 from thaJeztah/version
...
version 29.6.1
v29.6.1
2026-06-25 22:08:24 +02:00
Sebastiaan van Stijn and GitHub
22b8f1396e
Merge pull request #7069 from docker-agent/auto/migrate-to-docker-agent-action
...
chore: migrate cagent-action to docker-agent-action (v2.0.0)
2026-06-25 22:05:29 +02:00
Sebastiaan van Stijn
d9c59c9cfe
version 29.6.1
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-25 22:03:12 +02:00
Sebastiaan van Stijn and GitHub
64307515e6
Merge pull request #7073 from thaJeztah/bump_moby_user
...
vendor: github.com/moby/sys/user v0.4.1
2026-06-25 21:59:18 +02:00
Sebastiaan van Stijn
8fda97b545
vendor: github.com/moby/sys/user v0.4.1
...
- user: prevent possible DoS via unbounded parsing of user and group
database files in GHSA-mjcv-p78q-w5fw. This fixes a similar issue
as CVE-2026-47262 in containerd.
- user: prevent falling back to looking up numeric usernames
Improve handling of numeric user/group to prevent looking up numeric
values as usernames. This fixes a similar issue as [CVE-2026-46680] in
containerd.
- user: update minimum go version to go1.18
- assorted testing and linting fixes.
[CVE-2026-46680]: https://github.com/advisories/GHSA-fqw6-gf59-qr4w
full diff: https://github.com/moby/sys/compare/user/v0.4.0...user/v0.4.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-25 21:31:42 +02:00
Docker Agent
f9dc4e413b
chore: bump docker-agent-action to v2.0.1
...
Signed-off-by: Docker Agent <svc-github-docker-agent@docker.com >
2026-06-24 13:32:46 +00:00
Sebastiaan van Stijn and GitHub
f8a2d2b253
Merge pull request #7070 from docker/dependabot/github_actions/actions/checkout-7.0.0
...
build(deps): bump actions/checkout from 6.0.3 to 7.0.0
2026-06-24 10:48:34 +02:00
dependabot[bot] and GitHub
7eb15d3454
build(deps): bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-24 08:42:35 +00:00
Sebastiaan van Stijn and GitHub
033b0ff9ff
Merge pull request #7063 from docker/dependabot/github_actions/crazy-max/dot-github/dot-github/workflows/zizmor.yml-1.10.1
...
build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml from 1.10.0 to 1.10.1
2026-06-22 16:42:54 +02:00
Sebastiaan van Stijn and GitHub
317bfd1231
Merge pull request #7067 from docker/dependabot/github_actions/docker/cagent-action/dot-github/workflows/review-pr.yml-1.5.5
...
build(deps): bump docker/cagent-action/.github/workflows/review-pr.yml from 1.5.4 to 1.5.5
2026-06-22 16:41:07 +02:00
Sebastiaan van Stijn and GitHub
1b4c7d7807
Merge pull request #7068 from thaJeztah/bump_version
...
bump VERSION to v29.7.0-dev
2026-06-22 16:39:50 +02:00
Sebastiaan van Stijn
e45822e51d
bump VERSION to v29.7.0-dev
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-22 15:52:40 +02:00
dependabot[bot] and GitHub
a97303090d
build(deps): bump docker/cagent-action/.github/workflows/review-pr.yml
...
Bumps [docker/cagent-action/.github/workflows/review-pr.yml](https://github.com/docker/cagent-action ) from 1.5.4 to 1.5.5.
- [Release notes](https://github.com/docker/cagent-action/releases )
- [Commits](https://github.com/docker/cagent-action/compare/3f5dc9969f307d3c76acb7e9ccaefdd96bd62f4b...367a30ddb41e0156459d03750f508eac03f3c38a )
---
updated-dependencies:
- dependency-name: docker/cagent-action/.github/workflows/review-pr.yml
dependency-version: 1.5.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-22 08:43:57 +00:00
dependabot[bot] and GitHub
d516a10f93
build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml
...
Bumps [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github ) from 1.10.0 to 1.10.1.
- [Release notes](https://github.com/crazy-max/.github/releases )
- [Commits](https://github.com/crazy-max/.github/compare/716fd1c51a46c5d93a41d44a94b439c9ee802536...46267a6e61cd56aac2fc79943df180152f4c89d6 )
---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
dependency-version: 1.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 08:42:27 +00:00
Sebastiaan van Stijn and GitHub
fb59821d45
Merge pull request #7062 from vvoland/update-docker
...
vendor: github.com/moby/moby api v1.55.0 and client v0.5.0
v29.6.0
2026-06-18 21:53:10 +02:00
Paweł Gronowski
ee2f737013
vendor: github.com/moby/moby/client v0.5.0
...
full diff: https://github.com/moby/moby/compare/client/v0.5.0-rc.1...client/v0.5.0
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-06-18 21:41:38 +02:00
Paweł Gronowski
1f80e23560
vendor: github.com/moby/moby/api v1.55.0
...
full diff: https://github.com/moby/moby/compare/api/v1.55.0-rc.1...api/v1.55.0
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-06-18 21:39:19 +02:00
Paweł Gronowski and GitHub
1d1562e004
Merge pull request #7029 from agirault/login-password-dash-stdin
...
cli/registry: support password dash stdin
v29.6.0-rc.1
2026-06-12 19:31:17 +02:00
Sebastiaan van Stijn and GitHub
8c2e80070b
Merge pull request #7051 from thaJeztah/bump_moby
...
vendor: github.com/moby/moby/api v1.55.0-rc.1, moby/client v0.5.0-rc.1
2026-06-12 19:07:07 +02:00
Sebastiaan van Stijn
233cd4a643
vendor: github.com/moby/moby/api v1.55.0-rc.1, moby/client v0.5.0-rc.1
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-12 18:54:32 +02:00
Paweł Gronowski and GitHub
5b600d015d
Merge pull request #7047 from thaJeztah/bump_go_events
...
vendor: github.com/docker/go-events v0.0.0-20260608200158-dbf6103125a4
2026-06-12 18:44:35 +02:00
Paweł Gronowski and GitHub
e6decf4d85
Merge pull request #7048 from thaJeztah/bump_compress
...
vendor: github.com/klauspost/compress v1.18.6
2026-06-12 18:44:24 +02:00
Paweł Gronowski and GitHub
a9284d1161
Merge pull request #7049 from thaJeztah/bump_x_net
...
vendor: golang.org/x/net v0.56.0
2026-06-12 18:44:11 +02:00