This release keeps dependencies and maintenance posture current for teams operating this tool.
Published 19d
Containers & Orchestration
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
docker
go
orchestration
Summary
AI summaryUpdates ⚙️ Dependencies, deps, and 🔧 Internal across a mixed release.
Full changelog
What's Changed
🔧 Internal
- Ci: add concurrency group to pr-review-trigger to prevent duplicate reviews by @derekmisler in https://github.com/docker/compose/pull/13890
- Fix grammar in Attestations field comment by @blackflytech in https://github.com/docker/compose/pull/13891
- Ci: remove unused desktop-edge-test workflow by @thaJeztah in https://github.com/docker/compose/pull/13897
- Ci: zizmor workflow by @crazy-max in https://github.com/docker/compose/pull/13901
- Ci: fix docs-upstream workflow by @crazy-max in https://github.com/docker/compose/pull/13912
- CODEOWNERS: add compose-reviewers by @thaJeztah in https://github.com/docker/compose/pull/13913
- Ci: harden GitHub Actions workflows by @glours in https://github.com/docker/compose/pull/13896
- GHA: dependabot: group docker/* actions updates by @thaJeztah in https://github.com/docker/compose/pull/13914
⚙️ Dependencies
- Build(deps): bump github.com/moby/buildkit from
0.31.0to0.31.1by @dependabot[bot] in https://github.com/docker/compose/pull/13892 - Build(deps): bump github.com/moby/sys/user to
v0.4.1by @thaJeztah in https://github.com/docker/compose/pull/13893 - Build(deps): bump go.yaml.in/yaml/v4 from
4.0.0-rc.4to4.0.0-rc.6by @dependabot[bot] in https://github.com/docker/compose/pull/13876 - Build(deps): bump github.com/docker/cli from
29.6.0+incompatibleto29.6.1+incompatibleby @dependabot[bot] in https://github.com/docker/compose/pull/13895 - Build(deps): bump actions/stale from
10.2.0to10.3.0by @dependabot[bot] in https://github.com/docker/compose/pull/13902 - Build(deps): bump the docker-actions group with 3 updates by @dependabot[bot] in https://github.com/docker/compose/pull/13916
- Build(deps): bump actions/upload-artifact from
7.0.0to7.0.1by @dependabot[bot] in https://github.com/docker/compose/pull/13908 - Build(deps): bump actions/setup-go from
6.3.0to6.5.0by @dependabot[bot] in https://github.com/docker/compose/pull/13907 - Build(deps): bump test-summary/action from
2.4to2.6by @dependabot[bot] in https://github.com/docker/compose/pull/13903 - Build(deps): bump mxschmitt/action-tmate from
3.23to3.24by @dependabot[bot] in https://github.com/docker/compose/pull/13910 - Build(deps): bump codecov/codecov-action from
5.5.3to7.0.0by @dependabot[bot] in https://github.com/docker/compose/pull/13904 - Build(deps): bump github/codeql-action/upload-sarif from
3.36.3to4.36.2by @dependabot[bot] in https://github.com/docker/compose/pull/13917 - Build(deps): bump actions/checkout from
6.0.2to7.0.0by @dependabot[bot] in https://github.com/docker/compose/pull/13911
New Contributors
- @blackflytech made their first contribution in https://github.com/docker/compose/pull/13891
Full Changelog: https://github.com/docker/compose/compare/v5.3.0...v5.3.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]