Page MenuHomePhabricator

Buildkit v0.31.2 released
Closed, ResolvedPublic

Description

This is a security patch release with four moderate and one low severity security fixes.

Notable Changes
Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
Possible panic when incorrect parameters sent from frontend. GHSA-qx3x-mv6r-52p6
LLB file operation can be tricked to remove /tmp directory contents. GHSA-32pv-7hq5-qhwq
Malicious client can bypass destination directory validation on local sources upload. https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976
WCOW cache mount source selector resolves NTFS junctions outside of cache root. https://github.com/moby/buildkit/security/advisories/GHSA-388v-wmr2-g2v2
Fix possible buildctl failures after successful builds over slow connhelper transports. #6940
Fix possible daemon crash during concurrent builds. #6916
Deployment:

  • gitlab-cloud-runners staging
  • gitlab-cloud-runners production
  • WMCS and Trusted runners

Details

Related Changes in Gerrit:
Related Changes in GitLab:
TitleReferenceAuthorSource BranchDest Branch
staging and prod: Use buildkitd wmf-v0.31.2 [auto-approve]repos/releng/gitlab-cloud-runner!622dancymain-I74ccefa757330f4d0c23bc5eb11229a3678d7639main
Customize query in GitLab

Event Timeline

Mentioned in SAL (#wikimedia-releng) [2026-07-16T18:51:29Z] <dancy> Updated buildkit to v0.31.2 gitlab-cloud-runners (staging and production) (T432360)

Change #1311523 had a related patch set uploaded (by Ahmon Dancy; author: Ahmon Dancy):

[operations/puppet@production] buildkitd: Bump buildkit image to wmf-v0.31.2

https://gerrit.wikimedia.org/r/1311523

Change #1311523 merged by Dzahn:

[operations/puppet@production] buildkitd: Bump buildkit image to wmf-v0.31.2

https://gerrit.wikimedia.org/r/1311523

dancy claimed this task.
dancy triaged this task as High priority.
dancy updated the task description. (Show Details)
dancy added a subscriber: dduvall.