An open index of dependabot pull requests across open source projects.

build(deps): bump github.com/moby/buildkit from 0.31.0 to 0.31.1

Closed
Number: #14
Type: Pull Request
State: Closed
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: July 01, 2026 at 09:17 PM UTC
(29 days ago)
Updated: July 10, 2026 at 04:37 PM UTC
(20 days ago)
Closed: July 10, 2026 at 04:37 PM UTC
(20 days ago)
Time to Close: 9 days
Labels:
dependencies go
Description:

Bumps github.com/moby/buildkit from 0.31.0 to 0.31.1.

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.31.1

buildkit 0.31.1

Welcome to the v0.31.1 release of buildkit!

This is a security patch release with two low severity security fixes.

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi

Notable Changes

Dependency Changes

This release has no dependency changes

Previous release can be found at v0.31.0

Commits
  • 673b7e0 Merge pull request #6896 from tonistiigi/v0.31.1-picks
  • 81ce1c6 ci: tolerate empty test matrix includes
  • 69a3924 user: limit size of parsed passwd/group files
  • 3ea6dd0 security: validate exec security modes
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Ecosystem:
go
Version Change:
0.31.0 → 0.31.1
Update Type:
Patch
Technical Details
ID: 16126021
UUID: 4789278883
Node ID: PR_kwDOSPcun87s3V7F
Host: GitHub
Repository: CodeLinaro-mirror/yocto-mirrors_github_docker_compose