1cbf22ed24
Accepting request 1287936 from home:cyphar:docker
Aleksa Sarai2025-06-23 13:07:50 +00:00
4f0ef3de34
[ This update is a no-op, only needed to work around unfortunate automated packaging script behaviour on SLES. ]
Aleksa Sarai2025-06-23 12:56:51 +00:00
bd87ff5b8b
Accepting request 1287934 from home:cyphar:docker
Aleksa Sarai2025-06-23 12:56:51 +00:00
ed61589e0d
Accepting request 1283419 from Virtualization:containers
Ana Guerrero2025-06-10 06:57:46 +00:00
92ea9832f7
Accepting request 1283419 from Virtualization:containers
Ana Guerrero2025-06-10 06:57:46 +00:00
6a7742a591
Accepting request 1283414 from home:cyphar:docker
Aleksa Sarai2025-06-05 16:34:25 +00:00
1f58d49808
- Do not try to inject SUSEConnect secrets when in Rootless Docker mode, as Docker does not have permission to access the host zypper credentials in this mode (and unprivileged users cannot disable the feature using /etc/docker/suse-secrets-enable.) bsc#1240150
Aleksa Sarai2025-06-05 16:19:52 +00:00
74aa876e7f
Accepting request 1283412 from home:cyphar:docker
Aleksa Sarai2025-06-05 16:19:52 +00:00
cb1fadaa4b
- Always clear SUSEConnect suse_* secrets when starting containers regardless of whether the daemon was built with SUSEConnect support. Not doing this causes containers from SUSEConnect-enabled daemons to fail to start when running with SUSEConnect-disabled (i.e. upstream) daemons.
Aleksa Sarai2025-06-04 06:14:23 +00:00
2c75c396ba
Accepting request 1282502 from home:cyphar:docker
Aleksa Sarai2025-06-04 06:14:23 +00:00
69630be04c
Accepting request 1281542 from Virtualization:containers
Ana Guerrero2025-06-02 19:59:08 +00:00
646f517b6a
Accepting request 1281542 from Virtualization:containers
Ana Guerrero2025-06-02 19:59:08 +00:00
37241ca5cc
- Update to Docker 28.2.2-ce. See upstream changelog online at <https://github.com/moby/moby/releases/tag/v28.2.2> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
Aleksa Sarai2025-05-30 17:59:48 +00:00
c48f9ef5ad
Accepting request 1281540 from home:cyphar:docker
Aleksa Sarai2025-05-30 17:59:48 +00:00
3f2382a8b2
- Update to Docker 28.2.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2820> bsc#1243833 - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Update to docker-buildx v0.24.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.24.0>
Aleksa Sarai2025-05-30 09:46:29 +00:00
1d9af5c3dd
Accepting request 1281342 from home:cyphar:docker
Aleksa Sarai2025-05-30 09:46:29 +00:00
ba29e28bc2
- Update to Docker 28.1.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2811> bsc#1242114 Includes upstream fixes: - CVE-2025-22872 bsc#1241830 - Remove long-outdated build handling for deprecated and unsupported devicemapper and AUFS storage drivers. AUFS was removed in v24, and devicemapper was removed in v25. <https://docs.docker.com/engine/deprecated/#aufs-storage-driver> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Remove upstreamed patches: - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - cli-0001-docs-include-required-tools-in-source-tree.patch - Update to docker-buildx v0.23.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.23.0>
Aleksa Sarai2025-05-01 17:17:53 +00:00
3d62bf805d
Accepting request 1273867 from home:cyphar:docker
Aleksa Sarai2025-05-01 17:17:53 +00:00
d1bd3c357c
Accepting request 1268264 from Virtualization:containers
Ana Guerrero2025-04-11 14:45:32 +00:00
a45689df88
Accepting request 1268264 from Virtualization:containers
Ana Guerrero2025-04-11 14:45:32 +00:00
212e67e0d3
- Update to docker-buildx v0.22.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.22.0> * Includes fixes for CVE-2025-0495. bsc#1239765 - Disable transparent SUSEConnect support for SLE-16. PED-12534 When this patchset was first added in 2013 (and rewritten over the years), there was no upstream way to easily provide SLE customers with a way to build container images based on SLE using the host subscription. However, with docker-buildx you can now define secrets for builds (this is not entirely transparent, but we can easily document this new requirement for SLE-16). Users should use RUN --mount=type=secret,id=SCCcredentials zypper -n ... in their Dockerfiles, and docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file . when doing their builds. - Now that the only blocker for docker-buildx support was removed for SLE-16, enable docker-buildx for SLE-16 as well. PED-8905
Aleksa Sarai2025-04-10 03:37:01 +00:00
3b9cf36d33
Accepting request 1268262 from home:cyphar:docker
Aleksa Sarai2025-04-10 03:37:01 +00:00
cffd8cbd08
- Don't use the new container-selinux conditional requires on SLE-12, as the RPM version there doesn't support it. Arguably the change itself is a bit suspect but we can fix that later. bsc#1237367
Aleksa Sarai2025-03-26 02:43:19 +00:00
3629cc6207
Accepting request 1256098 from home:cyphar:docker
Aleksa Sarai2025-03-26 02:43:19 +00:00