Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 30, 2025

Bumps github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible.

Release notes

Sourced from github.com/docker/docker's releases.

v28.3.3

28.3.3

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release fixes an issue where, after a firewalld reload, published container ports could be accessed directly from the local network, even when they were intended to be accessible only via a loopback address. CVE-2025-54388 / GHSA-x4rx-4gw3-53p4 / moby/moby#50506.

Packaging updates

Go SDK

  • cli/command/formatter: add TrunateID() utility as alternative for github.com/docker/docker/pkg/stringid.TrunateID(). docker/cli#6180
Commits
  • bea959c Merge pull request #50506 from robmry/backport-28.x/fix_firewalld_reload
  • 3e9ff78 bridge: Reapply endpoint iptables rules on firewalld reload
  • 29ed80a bridge: Trigger firewalld reload during bridge integration tests
  • da489a1 Merge pull request #50478 from thaJeztah/28.x_backport_gha_bump_bk
  • f173e45 Merge pull request #50480 from austinvazquez/cherry-pick-ea29dffaa541289591aa...
  • e4b1f89 daemon/server: remove compatibility with API v1.4 auth-config on push
  • 0c9e14d hack/buildkit-ref: temporarily bump BuildKit to head of v0.23 branch
  • bf6d688 Merge pull request #50471 from austinvazquez/cherry-pick-b1ce0c89f0214cc6711c...
  • 4205776 client: always send (empty) body on push
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 30, 2025
@dependabot dependabot bot requested a review from a team as a code owner July 30, 2025 09:15
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jul 30, 2025
@dependabot dependabot bot requested a review from ndeloof July 30, 2025 09:15
@dependabot dependabot bot added the go Pull requests that update Go code label Jul 30, 2025
@dependabot dependabot bot requested a review from glours July 30, 2025 09:15
@glours glours enabled auto-merge (rebase) July 30, 2025 09:15
Bumps [github.com/docker/docker](https://github.com/docker/docker) from 28.3.2+incompatible to 28.3.3+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](moby/moby@v28.3.2...v28.3.3)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-version: 28.3.3+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@glours glours force-pushed the dependabot/go_modules/github.com/docker/docker-28.3.3incompatible branch from 3b62326 to 293f556 Compare July 30, 2025 09:27
@glours glours merged commit 0dc9852 into main Jul 30, 2025
28 checks passed
@glours glours deleted the dependabot/go_modules/github.com/docker/docker-28.3.3incompatible branch July 30, 2025 09:39
tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request Aug 11, 2025
This MR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker/compose](https://github.com/docker/compose) | patch | `v2.39.1` -> `v2.39.2` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>docker/compose (docker/compose)</summary>

### [`v2.39.2`](https://github.com/docker/compose/releases/tag/v2.39.2)

[Compare Source](docker/compose@v2.39.1...v2.39.2)

#### What's Changed

##### 🐛 Fixes

- Fix (regression): compose build render build output with tty support by [@&#8203;ndeloof](https://github.com/ndeloof) in docker/compose#13107
- Add missing `_MODEL` suffix to model variable pass to dependent services of a model by [@&#8203;glours](https://github.com/glours) in docker/compose#13109
- Apply `BUILDKIT_PROGRESS` value when building with bake by [@&#8203;glours](https://github.com/glours) in docker/compose#13110
- Define `pull` and `no_cache` from either service or flags values when building with bake by [@&#8203;glours](https://github.com/glours) in docker/compose#13133
- Only monitor attached services on `up` command by [@&#8203;glours](https://github.com/glours) in docker/compose#13114

##### 🔧  Internal

- Add Streams Comment by [@&#8203;suwakei](https://github.com/suwakei) in docker/compose#13103
- Add test of `json.go` by [@&#8203;suwakei](https://github.com/suwakei) in docker/compose#13106
- Refactoring of redundant condition checks by [@&#8203;suwakei](https://github.com/suwakei) in docker/compose#13104
- Eliminated magic string by [@&#8203;suwakei](https://github.com/suwakei) in docker/compose#13105
- Use log API for containers we didn't attached to by [@&#8203;ndeloof](https://github.com/ndeloof) in docker/compose#13111
- Use `cli-plugins/metadata` package by [@&#8203;thaJeztah](https://github.com/thaJeztah) in docker/compose#13130
- `pkg/compose`: simplify getting auth-config key by [@&#8203;thaJeztah](https://github.com/thaJeztah) in docker/compose#13120
- Add go as a prerequisite in build instructions by [@&#8203;mattrunyon](https://github.com/mattrunyon) in docker/compose#13131

##### ⚙️ Dependencies

- Build(deps): bump github.com/docker/cli from `28.3.2+incompatible` to `28.3.3+incompatible` by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in docker/compose#13116
- Build(deps): bump github.com/docker/docker from `28.3.2+incompatible` to `28.3.3+incompatible` by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in docker/compose#13115
- Build(deps): bump github.com/containerd/containerd/v2 from `2.1.3` to `2.1.4` by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in docker/compose#13119
- Build(deps): bump github.com/docker/go-connections from `0.5.0` to `0.6.0` by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in docker/compose#13137
- Build(deps): bump golang.org/x/sys from `0.34.0` to `0.35.0` by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in docker/compose#13138
- Bump golang to `1.23.12` by [@&#8203;austinvazquez](https://github.com/austinvazquez) in docker/compose#13142

#### New Contributors

- [@&#8203;mattrunyon](https://github.com/mattrunyon) made their first contribution in docker/compose#13131
- [@&#8203;austinvazquez](https://github.com/austinvazquez) made their first contribution in docker/compose#13142

**Full Changelog**: docker/compose@v2.39.1...v2.39.2

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS41OC4yIiwidXBkYXRlZEluVmVyIjoiNDEuNTguMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90Il19-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant