Skip to content

Xxc - #1

Open
StasOnGazon wants to merge 1897 commits into
bamurtaugh:mainfrom
buildpacks:main
Open

Xxc#1
StasOnGazon wants to merge 1897 commits into
bamurtaugh:mainfrom
buildpacks:main

Conversation

@StasOnGazon

Copy link
Copy Markdown

Summary

Output

Before

After

Documentation

  • Should this change be documented?
    • Yes, see #___
    • No

Related

Resolves #___

hhiroshell and others added 30 commits September 5, 2024 20:09
Signed-off-by: Hiroshi Hayakawa <hhiroshell@gmail.com>
`createEphemeralBuilder` mutates the provided `rawBuilderImage`, so we must save the image name
before this method is called.

Signed-off-by: Natalie Arellano <narellano@vmware.com>
…s actually expected.

Fixes #2253

Signed-off-by: Damanpreet Singh <daman.4880@gmail.com>
Don't warn about clear-env key while parsing buildpack.toml as this is actually expected.
…ified image name exists

Signed-off-by: Hiroshi Hayakawa <hhiroshell@gmail.com>
Signed-off-by: Hiroshi Hayakawa <hhiroshell@gmail.com>
Signed-off-by: hhiroshell <hhiroshell@gmail.com>
…chore/scan-action-4

build(deps): bump anchore/scan-action from 3 to 4
Bumps [buildpacks/github-actions](https://github.com/buildpacks/github-actions) from 5.5.4 to 5.7.4.
- [Release notes](https://github.com/buildpacks/github-actions/releases)
- [Commits](buildpacks/github-actions@v5.5.4...v5.7.4)

---
updated-dependencies:
- dependency-name: buildpacks/github-actions
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…ildpacks/github-actions-5.7.4

build(deps): bump buildpacks/github-actions from 5.5.4 to 5.7.4
Bumps [github.com/docker/docker](https://github.com/docker/docker) from 26.1.4+incompatible to 26.1.5+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](moby/moby@v26.1.4...v26.1.5)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/docker/docker-26.1.5incompatible

build(deps): bump github.com/docker/docker from 26.1.4+incompatible to 26.1.5+incompatible
…s for each '--path' flag case to ensure no temp directories are left behind in case of a test failure.

Signed-off-by: Hiroshi Hayakawa <hhiroshell@gmail.com>
Make the `pack build` warn that the positional argument will not be treated as the source directory path
Signed-off-by: Natalie Arellano <narellano@vmware.com>
Signed-off-by: Natalie Arellano <narellano@vmware.com>
Signed-off-by: Natalie Arellano <narellano@vmware.com>
… docker

Signed-off-by: Natalie Arellano <narellano@vmware.com>


Signed-off-by: Natalie Arellano <narellano@vmware.com>
Signed-off-by: Natalie Arellano <narellano@vmware.com>
Bumps [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt) from 4.5.0 to 4.5.1.
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md)
- [Commits](golang-jwt/jwt@v4.5.0...v4.5.1)

---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/golang-jwt/jwt/v4-4.5.1

build(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1
Bumps [buildpacks/github-actions](https://github.com/buildpacks/github-actions) from 5.7.4 to 5.8.0.
- [Release notes](https://github.com/buildpacks/github-actions/releases)
- [Commits](buildpacks/github-actions@v5.7.4...v5.8.0)

---
updated-dependencies:
- dependency-name: buildpacks/github-actions
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…ildpacks/github-actions-5.8.0

build(deps): bump buildpacks/github-actions from 5.7.4 to 5.8.0
dependabot Bot and others added 30 commits March 27, 2026 06:37
Bumps the go-dependencies group with 2 updates: [github.com/chainguard-dev/kaniko](https://github.com/chainguard-dev/kaniko) and [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry).


Updates `github.com/chainguard-dev/kaniko` from 1.25.11 to 1.25.12
- [Release notes](https://github.com/chainguard-dev/kaniko/releases)
- [Changelog](https://github.com/chainguard-forks/kaniko/blob/main/CHANGELOG.md)
- [Commits](chainguard-forks/kaniko@v1.25.11...v1.25.12)

Updates `github.com/google/go-containerregistry` from 0.21.2 to 0.21.3
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.2...v0.21.3)

---
updated-dependencies:
- dependency-name: github.com/chainguard-dev/kaniko
  dependency-version: 1.25.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/moby/buildkit](https://github.com/moby/buildkit) from 0.26.3 to 0.28.1.
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.26.3...v0.28.1)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.28.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… updates (#2563)

Bumps the go-dependencies group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/docker/cli](https://github.com/docker/cli) | `29.3.0+incompatible` | `29.3.1+incompatible` |
| [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.17.0` | `5.17.2` |
| [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.3` | `0.21.4` |
| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.0` | `1.54.1` |
| [github.com/moby/moby/client](https://github.com/moby/moby) | `0.3.0` | `0.4.0` |



Updates `github.com/docker/cli` from 29.3.0+incompatible to 29.3.1+incompatible
- [Commits](docker/cli@v29.3.0...v29.3.1)

Updates `github.com/go-git/go-git/v5` from 5.17.0 to 5.17.2
- [Release notes](https://github.com/go-git/go-git/releases)
- [Commits](go-git/go-git@v5.17.0...v5.17.2)

Updates `github.com/google/go-containerregistry` from 0.21.3 to 0.21.4
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.3...v0.21.4)

Updates `github.com/moby/moby/api` from 1.54.0 to 1.54.1
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.54.0...api/v1.54.1)

Updates `github.com/moby/moby/client` from 0.3.0 to 0.4.0
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.4.0/CHANGELOG.md)
- [Commits](moby/moby@v0.3.0...v0.4.0)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.3.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.17.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.54.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2577)

Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.2 to 5.18.0.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Commits](go-git/go-git@v5.17.2...v5.18.0)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.18.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…1 updates (#2580)

Bumps the go-dependencies group with 4 updates in the / directory: [github.com/chainguard-dev/kaniko](https://github.com/chainguard-dev/kaniko), [github.com/gdamore/tcell/v2](https://github.com/gdamore/tcell), [github.com/moby/moby/api](https://github.com/moby/moby) and [github.com/moby/moby/client](https://github.com/moby/moby).


Updates `github.com/chainguard-dev/kaniko` from 1.25.12 to 1.25.13
- [Release notes](https://github.com/chainguard-dev/kaniko/releases)
- [Changelog](https://github.com/chainguard-forks/kaniko/blob/main/CHANGELOG.md)
- [Commits](chainguard-forks/kaniko@v1.25.12...v1.25.13)

Updates `github.com/docker/cli` from 29.3.1+incompatible to 29.4.0+incompatible
- [Commits](docker/cli@v29.3.1...v29.4.0)

Updates `github.com/gdamore/tcell/v2` from 2.13.8 to 2.13.9
- [Release notes](https://github.com/gdamore/tcell/releases)
- [Changelog](https://github.com/gdamore/tcell/blob/main/CHANGESv3.md)
- [Commits](gdamore/tcell@v2.13.8...v2.13.9)

Updates `github.com/google/go-containerregistry` from 0.21.4 to 0.21.5
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.4...v0.21.5)

Updates `github.com/moby/moby/api` from 1.54.1 to 1.54.2
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.54.1...api/v1.54.2)

Updates `github.com/moby/moby/client` from 0.4.0 to 0.4.1
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.4.1/CHANGELOG.md)
- [Commits](moby/moby@v0.4.0...v0.4.1)

Updates `golang.org/x/crypto` from 0.49.0 to 0.50.0
- [Commits](golang/crypto@v0.49.0...v0.50.0)

Updates `golang.org/x/mod` from 0.34.0 to 0.35.0
- [Commits](golang/mod@v0.34.0...v0.35.0)

Updates `golang.org/x/sys` from 0.42.0 to 0.43.0
- [Commits](golang/sys@v0.42.0...v0.43.0)

Updates `golang.org/x/term` from 0.41.0 to 0.42.0
- [Commits](golang/term@v0.41.0...v0.42.0)

Updates `golang.org/x/text` from 0.35.0 to 0.36.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.35.0...v0.36.0)

---
updated-dependencies:
- dependency-name: github.com/chainguard-dev/kaniko
  dependency-version: 1.25.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/docker/cli
  dependency-version: 29.4.0+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/gdamore/tcell/v2
  dependency-version: 2.13.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.54.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: golang.org/x/crypto
  dependency-version: 0.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/mod
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/sys
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/term
  dependency-version: 0.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/text
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Fixes CVE-2026-27143 (Critical), CVE-2026-27140 (High),
CVE-2026-27144 (High), CVE-2026-32280 (High), CVE-2026-32281 (High),
CVE-2026-32283 (High), CVE-2026-32282 (Medium), CVE-2026-32288 (Medium),
and CVE-2026-32289 (Medium) in the Go standard library by bumping the
minimum Go version to 1.25.9.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Mirror the ignore list used by buildpacks/lifecycle for the same
reasons: pack uses docker/docker as a client only, so daemon-side
vulnerabilities (plugin install privilege validation, AuthZ plugin
bypass) are not reachable from pack's code paths. Grype also flags
two long-standing protobuf false positives that are already filtered
by lifecycle.

This silences the scheduled check-latest-release.yml grype scan,
which currently fails on:
- GHSA-pxq6-2prw-chj9 (Medium)
- GHSA-x744-4wpc-v9h2 (High)

Both are fixed upstream in github.com/moby/moby/v2 but not backported
to the github.com/docker/docker module, so grype cannot auto-resolve
them.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
…2585)

Bumps the go-dependencies group with 1 update: [github.com/docker/cli](https://github.com/docker/cli).


Updates `github.com/docker/cli` from 29.4.0+incompatible to 29.4.1+incompatible
- [Commits](docker/cli@v29.4.0...v29.4.1)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.4.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix(build): fetch builder per platform
Signed-off-by: Dushyant Dahiya <dushyantdahiya2@gmail.com>

* fix(acceptance): emit platform pull log before digest resolution in FetchForPlatform

Signed-off-by: Dushyant Dahiya <dushyantdahiya2@gmail.com>

---------

Signed-off-by: Dushyant Dahiya <dushyantdahiya2@gmail.com>
Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
…2554)

Bumps [yaml](https://github.com/eemeli/yaml) from 1.10.0 to 1.10.3.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v1.10.0...v1.10.3)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 1.10.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Removes [uuid](https://github.com/uuidjs/uuid). It's no longer used after updating ancestor dependency [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core). These dependencies need to be updated together.


Removes `uuid`

Updates `@actions/core` from 1.10.0 to 1.11.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core)

---
updated-dependencies:
- dependency-name: "@actions/core"
  dependency-version: 1.11.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: JamBalaya56562 <jambalaya.pyoncafe@outlook.jp>
Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
Bumps the go-dependencies group with 3 updates: [github.com/chainguard-dev/kaniko](https://github.com/chainguard-dev/kaniko), [github.com/docker/cli](https://github.com/docker/cli) and [github.com/onsi/gomega](https://github.com/onsi/gomega).


Updates `github.com/chainguard-dev/kaniko` from 1.25.13 to 1.25.14
- [Release notes](https://github.com/chainguard-dev/kaniko/releases)
- [Changelog](https://github.com/chainguard-forks/kaniko/blob/main/CHANGELOG.md)
- [Commits](chainguard-forks/kaniko@v1.25.13...v1.25.14)

Updates `github.com/docker/cli` from 29.4.1+incompatible to 29.4.2+incompatible
- [Commits](docker/cli@v29.4.1...v29.4.2)

Updates `github.com/onsi/gomega` from 1.39.1 to 1.40.0
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](onsi/gomega@v1.39.1...v1.40.0)

---
updated-dependencies:
- dependency-name: github.com/chainguard-dev/kaniko
  dependency-version: 1.25.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/docker/cli
  dependency-version: 29.4.2+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2596)

Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.18.0 to 5.19.0.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.18.0...v5.19.0)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… updates (#2601)

Bumps the go-dependencies group with 4 updates in the / directory: [github.com/chainguard-dev/kaniko](https://github.com/chainguard-dev/kaniko), [github.com/docker/cli](https://github.com/docker/cli), [golang.org/x/crypto](https://github.com/golang/crypto) and [golang.org/x/mod](https://github.com/golang/mod).


Updates `github.com/chainguard-dev/kaniko` from 1.25.14 to 1.25.15
- [Release notes](https://github.com/chainguard-dev/kaniko/releases)
- [Changelog](https://github.com/chainguard-forks/kaniko/blob/main/CHANGELOG.md)
- [Commits](chainguard-forks/kaniko@v1.25.14...v1.25.15)

Updates `github.com/docker/cli` from 29.4.2+incompatible to 29.4.3+incompatible
- [Commits](docker/cli@v29.4.2...v29.4.3)

Updates `golang.org/x/crypto` from 0.50.0 to 0.51.0
- [Commits](golang/crypto@v0.50.0...v0.51.0)

Updates `golang.org/x/mod` from 0.35.0 to 0.36.0
- [Commits](golang/mod@v0.35.0...v0.36.0)

Updates `golang.org/x/sys` from 0.43.0 to 0.44.0
- [Commits](golang/sys@v0.43.0...v0.44.0)

Updates `golang.org/x/term` from 0.42.0 to 0.43.0
- [Commits](golang/term@v0.42.0...v0.43.0)

Updates `golang.org/x/text` from 0.36.0 to 0.37.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.36.0...v0.37.0)

---
updated-dependencies:
- dependency-name: github.com/chainguard-dev/kaniko
  dependency-version: 1.25.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/docker/cli
  dependency-version: 29.4.3+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: golang.org/x/crypto
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/mod
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/sys
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/term
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/text
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps minimum Go version from 1.25.9 to 1.25.10 in go.mod to address
stdlib vulnerabilities flagged by grype scans in #2595 and #2600.

Follows the same pattern as #2581.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Bumps minimum Go version from 1.25.9 to 1.25.10 in go.mod to address
stdlib vulnerabilities flagged by grype scans in #2595 and #2600.

Follows the same pattern as #2581.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Signed-off-by: Rune Soerensen <rsoerensen@salesforce.com>
Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
* Add failing test for builder inspect not trusting known builders

Signed-off-by: Rune Soerensen <rsoerensen@salesforce.com>

* Check known trusted builders in builder inspect

Signed-off-by: Rune Soerensen <rsoerensen@salesforce.com>

---------

Signed-off-by: Rune Soerensen <rsoerensen@salesforce.com>
Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
Following the GA release of the Heroku-26 stack, switch the suggested
Heroku builder from `heroku/builder:24` to `heroku/builder:26`. The
:24 builder remains trusted but is no longer suggested.

Also re-sync the :26 description with what's in our `builder.toml`
config.

See:
https://devcenter.heroku.com/changelog-items/3703
https://github.com/heroku/cnb-builder-images/blob/main/builder-26/builder.toml

Signed-off-by: Rune Soerensen <rsoerensen@salesforce.com>
* chore: remove direct dependency on github.com/docker/docker

Migrates the remaining github.com/docker/docker helper-package imports
left over after #2512, so the deprecated module is no longer a direct
dependency of pack. It now appears only as an indirect requirement via
other modules in the build graph.

Replacements:
- pkg/stdcopy        -> github.com/moby/moby/api/pkg/stdcopy
                       (termui fake gets a local 8-byte frame writer,
                        since the new package does not export NewStdWriter)
- pkg/jsonmessage    -> github.com/moby/moby/client/pkg/jsonmessage
                       (testhelpers switches to jsonstream.Message)
- pkg/ioutils        -> internal/ioutil.NewReadCloserWrapper
- pkg/homedir        -> os.UserHomeDir() wrapper
- daemon/names       -> local regexp constant (test only)
- volume/mounts      -> internal/volume Parser interface + a minimal,
                       parse-only Linux implementation. The Windows/LCOW
                       switch is dropped (pack supports Linux containers
                       only).

go mod tidy also drops several heavy transitive deps the old mounts
parser pulled in (opencontainers/selinux, cyphar.com/go-pathrs,
moby/sys/atomicwriter, morikuni/aec).

The internal/build/testdata/fake-lifecycle fixture module is left on
docker/docker for now; it is a separate Go module compiled inside its
own golang:1.23 image and does not contribute to pack's go.mod.

Refs #2470

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>

* chore: keep volume/mounts on docker/docker for LCOW/WCOW support

Revert the internal/volume parser introduced earlier in this branch.
The replacement was Linux-only and broke the Windows-host CI job
(pkg/client/build_test.go `on_windows/...` cases), which exercises both
Linux containers on Windows host (LCOW, e.g. `C:\path:/x`) and Windows
containers (WCOW, e.g. `C:\path:c:\x`). The docker/docker
volume/mounts package's Windows and LCOW parsers handle drive-letter-
aware splitting and source-path lowercasing that a Linux-only parser
cannot reproduce.

After this revert, github.com/docker/docker remains a direct dependency
solely through pkg/client/process_volumes.go (`volume/mounts`). All
other helper-package migrations in this branch are unaffected:
stdcopy, jsonmessage, ioutils, homedir, and daemon/names continue to
use their moby/moby split or stdlib replacements.

Removing the last volume/mounts usage requires either vendoring the
Windows/LCOW parsers or designing a unified parser; tracking that as
follow-up work on #2470.

Refs #2470

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>

---------

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Signed-off-by: MD-Mushfiqur123 <MD-Mushfiqur123@users.noreply.github.com>
Co-authored-by: MD-Mushfiqur123 <MD-Mushfiqur123@users.noreply.github.com>
Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
Bumps the security-relevant Go modules in isolation, split out of the
dependabot go-dependencies group (#2640) so the critical/high CVE fixes
can land without the moby/docker and go-containerregistry bumps that are
currently breaking acceptance tests:

- golang.org/x/crypto 0.51.0 -> 0.53.0 (GO-2026-5005/5006/5013-5023/5033)
- golang.org/x/net 0.53.0 -> 0.55.0 (GO-2026-5025-5030)
- github.com/go-git/go-git/v5 5.19.0 -> 5.19.1 (GHSA-crhj-59gh-8x96,
  GHSA-m7cr-m3pv-hgrp, GHSA-w5pp-99ch-qj29)

x/sync, x/sys, x/term, and x/text move forward transitively via x/crypto.

The moby/moby/client 0.5.0 + moby/moby/api 1.55.0 + docker/cli +
go-containerregistry 0.21.7 bumps from the group are intentionally held:
the daemon client jump is ahead of imgutil (pinned to moby/moby/client
0.2.x) and breaks daemon rebase, and ggcr 0.21.7 breaks manifest annotate.
None of those resolve a fixable CVE.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…2642)

CI build/test/release jobs install Go via go-version-file: go.mod, so the
go directive controls the stdlib version compiled into the release binary.
Bumping 1.25.10 -> 1.25.11 resolves the stdlib CVEs flagged by grype that
neither the dependabot module bumps nor go module updates can address:

- CVE-2026-42504 (GO-2026-5036), GO-2026-5038 (High)
- CVE-2026-27145 (GO-2026-5037), CVE-2026-42507 (GO-2026-5039) (Medium)

Dockerfile (golang:1.25) and benchmark.yml (go-version: 1.25) already
track the latest 1.25 patch, so no change is needed there.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The grype scan against the pack binary still flagged six docker findings
that our .grype.yaml intended to ignore. The existing ignore rules listed
the GHSA aliases, but grype matches the printed primary ID and the
go-module scan prints the GO-2026-* IDs, so the suppressions never fired.

All six are non-impactful for pack:

- docker/docker GO-2026-4887, GO-2026-4883, GHSA-x86f-5xw2-fm2r,
  GHSA-rg2x-37c3-w2rh, GHSA-vp62-88p7-qqf5 are daemon-side (AuthZ bypass,
  plugin-privilege off-by-one, docker cp races, decompression RCE). pack
  only uses docker as a client (api/types, client, volume/mounts, pkg/*
  helpers) and never runs the daemon paths. None are fixed in the
  github.com/docker/docker module; the fix exists only in the rewritten
  github.com/moby/moby/v2 module, which the ecosystem has not adopted.
- docker/cli GO-2026-4610 is already remediated: we ship v29.4.3, newer
  than the fixed v29.2.0; grype mis-orders the +incompatible version.

Listing every ID form (GO + GHSA) makes the suppressions apply across
both the go-module binary scan and the released-image scan. With this,
`grype out/pack` reports no vulnerabilities.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed off by: fossabot <badges@fossa.com>

Co-authored-by: Juan Bustamante <bustamantejj@gmail.com>
…#2647)

Splits the safe subset out of the grouped dependabot bump in #2645.

These four direct deps update without disturbing the docker/moby image
stack, so they keep acceptance green:

  - github.com/chainguard-dev/kaniko  v1.25.15 -> v1.25.16
  - github.com/gdamore/tcell/v2       v2.13.9  -> v2.13.10
  - github.com/onsi/gomega            v1.40.0  -> v1.42.1
  - golang.org/x/mod                  v0.36.0  -> v0.37.0

The moby/moby/{api,client}, go-containerregistry, and docker/cli bumps
from #2645 are intentionally held: imgutil still pins moby/moby/client
v0.2.2 / api v1.52.1 / go-containerregistry v0.20.6 even on its main tip,
so forcing pack ahead breaks the daemon rebase ("could not find base
layer in image") and manifest annotate acceptance suites.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Fixes the CVEs reported in #2652 and takes the safe subset of the
grouped dependabot bump in #2650.

The two CVEs failing the released-image grype scan are both stdlib,
fixed in Go 1.25.12, so the actual remediation is the go directive:

  - GO-2026-4970 (High)   root escape via symlink plus trailing slash in os
  - GO-2026-5856 (Medium) Encrypted Client Hello privacy leak in crypto/tls

CI builds with go-version-file: go.mod, so bumping the directive is
sufficient to rebuild the release image on 1.25.12.

Also takes the safe x/* bumps from #2650, which resolve without
disturbing the docker/moby image stack:

  - golang.org/x/crypto  v0.53.0 -> v0.54.0
  - golang.org/x/mod     v0.37.0 -> v0.38.0
  - golang.org/x/sync    v0.21.0 -> v0.22.0
  - golang.org/x/sys     v0.46.0 -> v0.47.0
  - golang.org/x/term    v0.44.0 -> v0.45.0
  - golang.org/x/text    v0.38.0 -> v0.40.0

The docker/cli, go-containerregistry and moby/moby/{api,client} bumps
from #2650 are held: imgutil still pins the older moby split-client, so
forcing pack ahead breaks daemon rebase and manifest annotate acceptance.
Tracked upstream in buildpacks/imgutil#307.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
)

Addresses the vulnerabilities grype reports against the released
v0.40.8 image:

- github.com/go-git/go-git/v5 v5.19.1 -> v5.19.2
  GHSA-hc8v-wwc9-vgxm (High), GHSA-qgq7-7hm3-q39j (Medium)
- go.opentelemetry.io/otel v1.43.0 -> v1.44.0
  GO-2026-5158 / CVE-2026-41178 (Medium), baggage header not length-capped
- github.com/klauspost/compress v1.18.6 -> v1.18.7
  GO-2026-5841 / GHSA-259r-337f-4rfw, OOB read in s2

The fifth finding, GO-2026-5932 on golang.org/x/crypto, has no fixed
version: it is the advisory marking golang.org/x/crypto/openpgp as
unmaintained, introduced at v0 with no fix, so it matches every release
of the module and cannot be remediated by bumping. pack does not link
that package -- its only importer is go-github/v30 through
acceptance/config, which sits behind the `acceptance` build tag and is
not part of the shipped binary. Suppressed in .grype.yaml with that
rationale; govulncheck agrees the code does not call it.

Deliberately scoped to these three modules. The moby/ggcr/docker-cli
group bump in #2663 also carries the go-git and compress fixes, but it
is being held back until imgutil supports the newer moby client.

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.