chore: bump github.com/moby/moby from 25.0.2+incompatible to 28.3.3+incompatible
Type: Pull Request
State: Closed
Association: Contributor
Comments: 1
(3 months ago)
(2 months ago)
(2 months ago)
stale dependencies go
Bumps github.com/moby/moby from 25.0.2+incompatible to 28.3.3+incompatible.
Release notes
Sourced from github.com/moby/moby's releases.
v28.3.3
28.3.3
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release fixes an issue where, after a firewalld reload, published container ports could be accessed directly from the local network, even when they were intended to be accessible only via a loopback address. CVE-2025-54388 / GHSA-x4rx-4gw3-53p4 / moby/moby#50506.
Packaging updates
- Update Buildx to v0.26.1. docker/docker-ce-packaging#1230
- Update Compose to v2.39.1. docker/docker-ce-packaging#1234
- Update Docker Model CLI plugin to v0.1.36. docker/docker-ce-packaging#1233
Go SDK
- cli/command/formatter: add
TrunateID()utility as alternative forgithub.com/docker/docker/pkg/stringid.TrunateID(). docker/cli#618028.3.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
- docker/cli, 28.3.2 milestone
- moby/moby, 28.3.2 milestone
- Deprecated and removed features, see Deprecated Features.
- Changes to the Engine API, see API version history.
Bug fixes and enhancements
- Fix
--use-api-socketnot working correctly when targeting a remote daemon. docker/cli#6157- Fix stray "otel error" logs being printed if debug logging is enabled. docker/cli#6160
- Quote SSH arguments when connecting to a remote daemon over an SSH connection to avoid unexpected expansion. docker/cli#6147
- Warn when
DOCKER_AUTH_CONFIGis set duringdocker loginanddocker logout. docker/cli#6163Packaging updates
- Update Compose to v2.38.2. docker/docker-ce-packaging#1225
- Update Docker Model CLI plugin to v0.1.33. docker/docker-ce-packaging#1227
- Update Go runtime to 1.24.5. moby/moby#50354
28.3.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
... (truncated)
Commits
bea959cMerge pull request #50506 from robmry/backport-28.x/fix_firewalld_reload3e9ff78bridge: Reapply endpoint iptables rules on firewalld reload29ed80abridge: Trigger firewalld reload during bridge integration testsda489a1Merge pull request #50478 from thaJeztah/28.x_backport_gha_bump_bkf173e45Merge pull request #50480 from austinvazquez/cherry-pick-ea29dffaa541289591aa...e4b1f89daemon/server: remove compatibility with API v1.4 auth-config on push0c9e14dhack/buildkit-ref: temporarily bump BuildKit to head of v0.23 branchbf6d688Merge pull request #50471 from austinvazquez/cherry-pick-b1ce0c89f0214cc6711c...4205776client: always send (empty) body on pushe77ff99Merge pull request #50354 from vvoland/50353-28.x- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
0
0
+0
-0
Package Dependencies
github.com/moby/moby
go
25.0.2+incompatible → 28.3.3+incompatible
Major
Technical Details
| ID: | 5158729 |
| UUID: | 3289698364 |
| Node ID: | PR_kwDOLmBl1M6iBKc9 |
| Host: | GitHub |
| Repository: | Txim0520/https-github.com-coder-coder |