This is a security patch release with four moderate and one low severity security fixes.
Notable Changes
Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
Possible panic when incorrect parameters sent from frontend. GHSA-qx3x-mv6r-52p6
LLB file operation can be tricked to remove /tmp directory contents. GHSA-32pv-7hq5-qhwq
Malicious client can bypass destination directory validation on local sources upload. https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976
WCOW cache mount source selector resolves NTFS junctions outside of cache root. https://github.com/moby/buildkit/security/advisories/GHSA-388v-wmr2-g2v2
Fix possible buildctl failures after successful builds over slow connhelper transports. #6940
Fix possible daemon crash during concurrent builds. #6916
Deployment:
- gitlab-cloud-runners staging
- gitlab-cloud-runners production
- WMCS and Trusted runners