moby / buildkit

concurrent, cache-efficient, and Dockerfile-agnostic builder toolkit
https://github.com/moby/moby/issues/34227
Apache License 2.0
8.05k stars 1.13k forks source link

new release of docker/dockerfile image to fix CVE-2024-41110 #5201

Open akhal3d96 opened 1 month ago

akhal3d96 commented 1 month ago

docker/dockerfile image is using github.com/docker/docker v27.0.3+incompatible as a dependency which is affected by CVE-2024-41110. I can see that the master branch already fixed this. Could you please release a new frontend image with a different tag :) ?

AkihiroSuda commented 1 month ago

False alarm. The dockerfile frontend does not use the authz plugin of dockerd.

AkihiroSuda commented 1 month ago

I marked this issue as "invalid", but I think it is still ok to make a release just for silencing the false alarm.

fiskhest commented 1 month ago

Hitting this in internal CI mirroring, can we get a new release please?