This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
Summary
AI summaryTwo low‑severity security fixes address custom frontend bypass and runtime DoS via unbounded group parsing.
Full changelog
buildkit 0.31.1
Welcome to the v0.31.1 release of buildkit!
This is a security patch release with two low severity security fixes.
Please try out the release binaries and report any issues at
https://github.com/moby/buildkit/issues.
Contributors
- Tõnis Tiigi
Notable Changes
- Custom frontend could bypass Seccomp/AppArmor restrictions https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6
- Possible runtime DoS via unbounded group parsing https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
Dependency Changes
This release has no dependency changes
Previous release can be found at v0.31.0
Security Fixes
- GHSA-7236-3392-c5c6 — Custom frontend could bypass Seccomp/AppArmor restrictions
- GHSA-72x6-4j93-7w86 — Possible runtime DoS via unbounded group parsing
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]