Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[26.1 backport] Dockerfile: update containerd binary to v1.7.16 (static binaries and CI only) #47841

Merged
merged 2 commits into from
May 22, 2024

Conversation

vvoland
Copy link
Contributor

@vvoland vvoland commented May 17, 2024

Update the containerd binary that's used in CI and static binaries

Update containerd (static binaries only) to [v1.7.17](https://github.com/containerd/containerd/releases/tag/v1.7.17)

Signed-off-by: Paweł Gronowski pawel.gronowski@docker.com

@thaJeztah
Copy link
Member

This one also needs the second commit from #47840

…CI only)

Update the containerd binary that's used in CI and static binaries

- full diff: containerd/containerd@v1.7.15...v1.7.17
- release notes: https://github.com/containerd/containerd/releases/tag/v1.7.17

```markdown changelog
Update containerd (static binaries only) to [v1.7.17](https://github.com/containerd/containerd/releases/tag/v1.7.17)
```

Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
(cherry picked from commit 4f0cb7d)
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
(cherry picked from commit 3847da3)
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
Copy link
Member

@thaJeztah thaJeztah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@thaJeztah thaJeztah merged commit 258a372 into moby:26.1 May 22, 2024
126 checks passed
renovate bot added a commit to earthly/dind that referenced this pull request Jun 10, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker/docker](https://togithub.com/docker/docker) | patch | `26.1.3`
-> `26.1.4` |

---

### Release Notes

<details>
<summary>docker/docker (docker/docker)</summary>

### [`v26.1.4`](https://togithub.com/moby/moby/releases/tag/v26.1.4)

[Compare
Source](https://togithub.com/docker/docker/compare/v26.1.3...v26.1.4)

#### 26.1.4

For a full list of pull requests and changes in this release, refer to
the relevant GitHub milestones:

- [docker/cli, 26.1.4
milestone](https://togithub.com/docker/cli/issues?q=is%3Aclosed+milestone%3A26.1.4)
- [moby/moby, 26.1.4
milestone](https://togithub.com/moby/moby/issues?q=is%3Aclosed+milestone%3A26.1.4)
- Deprecated and removed features, see [Deprecated
Features](https://togithub.com/docker/cli/blob/v26.1.4/docs/deprecated.md).
- Changes to the Engine API, see [API version
history](https://togithub.com/moby/moby/blob/v26.1.4/docs/api/version-history.md).

##### Security

This release updates the Go runtime to 1.21.11 which contains security
fixes for:

-   [CVE-2024-24789]
-   [CVE-2024-24790]
- A symlink time of check to time of use race condition during directory
removal reported by Addison Crump
([@&#8203;addisoncrump](https://togithub.com/addisoncrump)).

##### Bug fixes and enhancements

- Fixed an issue where promoting a node immediately after another node
was demoted could cause the promotion to fail.
[moby/moby#47870](https://togithub.com/moby/moby/pull/47870)
- Prevent the daemon log from being spammed with `superfluous
response.WriteHeader call ...` messages..
[moby/moby#47843](https://togithub.com/moby/moby/pull/47843)
- Don't show empty hints when plugins return an empty hook message.
[docker/cli#5083](https://togithub.com/docker/cli/pull/5083)
- Added `ContextType: "moby"` to the context list/inspect output to
address a compatibility issue with Visual Studio Container Tools.
[docker/cli#5095](https://togithub.com/docker/cli/pull/5095)
- Fix a compatibility issue with Visual Studio Container Tools.
[docker/cli#5095](https://togithub.com/docker/cli/pull/5095)

##### Packaging updates

- Update containerd (static binaries only) to
[v1.7.17](https://togithub.com/containerd/containerd/releases/tag/v1.7.17).
[moby/moby#47841](https://togithub.com/moby/moby/pull/47841)
- [CVE-2024-24789], [CVE-2024-24790]: Update Go runtime to 1.21.11.
[moby/moby#47904](https://togithub.com/moby/moby/pull/47904)
- Update Compose to
[v2.27.1](https://togithub.com/docker/compose/releases/tag/v2.27.1).
[docker/docker-ce-packages#1022](https://togithub.com/docker/docker-ce-packaging/pull/1022)
- Update Buildx to
[v0.14.1](https://togithub.com/docker/buildx/releases/tag/v0.14.1).
[docker/docker-ce-packages#1021](https://togithub.com/docker/docker-ce-packaging/pull/1021)

    [CVE-2024-24789]: https://togithub.com/golang/go/issues/66869

    [CVE-2024-24790]: https://togithub.com/golang/go/issues/67680

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "after 6am on monday" (UTC), Automerge
- At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/earthly/dind).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zOTMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjM5My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate bot added a commit to earthly/dind that referenced this pull request Jun 10, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker/docker](https://togithub.com/docker/docker) | patch | `26.1.3`
-> `26.1.4` |

---

### Release Notes

<details>
<summary>docker/docker (docker/docker)</summary>

### [`v26.1.4`](https://togithub.com/moby/moby/releases/tag/v26.1.4)

[Compare
Source](https://togithub.com/docker/docker/compare/v26.1.3...v26.1.4)

#### 26.1.4

For a full list of pull requests and changes in this release, refer to
the relevant GitHub milestones:

- [docker/cli, 26.1.4
milestone](https://togithub.com/docker/cli/issues?q=is%3Aclosed+milestone%3A26.1.4)
- [moby/moby, 26.1.4
milestone](https://togithub.com/moby/moby/issues?q=is%3Aclosed+milestone%3A26.1.4)
- Deprecated and removed features, see [Deprecated
Features](https://togithub.com/docker/cli/blob/v26.1.4/docs/deprecated.md).
- Changes to the Engine API, see [API version
history](https://togithub.com/moby/moby/blob/v26.1.4/docs/api/version-history.md).

##### Security

This release updates the Go runtime to 1.21.11 which contains security
fixes for:

-   [CVE-2024-24789]
-   [CVE-2024-24790]
- A symlink time of check to time of use race condition during directory
removal reported by Addison Crump
([@&#8203;addisoncrump](https://togithub.com/addisoncrump)).

##### Bug fixes and enhancements

- Fixed an issue where promoting a node immediately after another node
was demoted could cause the promotion to fail.
[moby/moby#47870](https://togithub.com/moby/moby/pull/47870)
- Prevent the daemon log from being spammed with `superfluous
response.WriteHeader call ...` messages..
[moby/moby#47843](https://togithub.com/moby/moby/pull/47843)
- Don't show empty hints when plugins return an empty hook message.
[docker/cli#5083](https://togithub.com/docker/cli/pull/5083)
- Added `ContextType: "moby"` to the context list/inspect output to
address a compatibility issue with Visual Studio Container Tools.
[docker/cli#5095](https://togithub.com/docker/cli/pull/5095)
- Fix a compatibility issue with Visual Studio Container Tools.
[docker/cli#5095](https://togithub.com/docker/cli/pull/5095)

##### Packaging updates

- Update containerd (static binaries only) to
[v1.7.17](https://togithub.com/containerd/containerd/releases/tag/v1.7.17).
[moby/moby#47841](https://togithub.com/moby/moby/pull/47841)
- [CVE-2024-24789], [CVE-2024-24790]: Update Go runtime to 1.21.11.
[moby/moby#47904](https://togithub.com/moby/moby/pull/47904)
- Update Compose to
[v2.27.1](https://togithub.com/docker/compose/releases/tag/v2.27.1).
[docker/docker-ce-packages#1022](https://togithub.com/docker/docker-ce-packaging/pull/1022)
- Update Buildx to
[v0.14.1](https://togithub.com/docker/buildx/releases/tag/v0.14.1).
[docker/docker-ce-packages#1021](https://togithub.com/docker/docker-ce-packaging/pull/1021)

    [CVE-2024-24789]: https://togithub.com/golang/go/issues/66869

    [CVE-2024-24790]: https://togithub.com/golang/go/issues/67680

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "after 6am on monday" (UTC), Automerge
- At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/earthly/dind).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zOTMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjM5My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants