Skip to content

Releases: moby/moby

v29.7.2

Choose a tag to compare

@vvoland vvoland released this 06 Aug 10:35
docker-v29.7.2
6a43e3d

29.7.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements

  • Fix docker service create and docker service update panicking when the same environment variable is passed more than once. docker/cli#7145
  • Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets, as produced by some image builders. moby/moby#53305
  • Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and docker cp to fail on older Linux kernels when applying file permissions, including for device nodes. moby/moby#53305

Packaging updates

Networking

  • Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon. moby/moby#53303

v29.7.1

Choose a tag to compare

@vvoland vvoland released this 31 Jul 17:36
docker-v29.7.1
c5b8ce9

29.7.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements

  • Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries. moby/moby#53260
  • Fix a regression where the CopyToContainer rejects container paths that traverse absolute symlinks, such as /var/run -> /run. moby/moby#53261

v29.7.0

Choose a tag to compare

@vvoland vvoland released this 30 Jul 21:38
docker-v29.7.0
4b5cb71

29.7.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New

  • Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898
  • Mount type image is no longer experimental. moby/moby#52998
  • Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146

Security

This release includes a fix for a security vulnerability affecting Docker Engine and related components.

Networking

  • Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network. moby/moby#53237
  • Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022

Rootless

Bug fixes and enhancements

  • Add shell completion for --filter names and known values to docker service ls, docker service ps, and docker node ps. docker/cli#7124
  • containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
    • To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
  • Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084
  • Fix docker cp from a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory. moby/moby#53123
  • Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101
  • Fix docker stats reporting empty network stats for running Windows containers when using the containerd runtime. moby/moby#53219
  • Fix a typo in the docker create --pull flag description. docker/cli#7103
  • Fix Swarm service updates failing due to "file exists" errors when a VIP IP alias already exists on the LB endpoint interface. moby/moby#51657
  • Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node. moby/moby#53212
  • Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
  • Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
  • Suppress the “No such container” error when docker rm --force succeeds for a nonexistent container. docker/cli#7110

Packaging updates

client/v0.5.1

Choose a tag to compare

@vvoland vvoland released this 27 Jul 19:09
client/v0.5.1
4555918

0.5.1

Changelog

  • client/pkg/jsonmessage: Display: fix godoc link. moby/moby#53070
  • client: ServiceCreate, ServiceUpdate: fix duplicate and 'unkown' platforms. moby/moby#53012
  • client: ServiceInspect, ContainerCommit: omit optional query args if not set. moby/moby#53010
  • golangci-lint: enable perfsprint linter. moby/moby#53016

v29.7.0-rc.1

v29.7.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@vvoland vvoland released this 28 Jul 09:01
docker-v29.7.0-rc.1
4555918

29.7.0-rc.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New

  • Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898

Bug fixes and enhancements

  • Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146
  • containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
    • To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
  • Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084
  • Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101
  • Fix a typo in the docker create --pull flag description. docker/cli#7103
  • Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
  • Mount type image is no longer experimental. moby/moby#52998
  • Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
  • Suppress the “No such container” error when docker rm --force succeeds for a nonexistent container. docker/cli#7110
  • Update Go runtime to 1.26.5. docker/cli#7087

Packaging updates

Networking

  • Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022

Rootless

v29.6.2

Choose a tag to compare

@vvoland vvoland released this 16 Jul 16:55
docker-v29.6.2
3d80467

29.6.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release includes fixes for multiple security vulnerabilities affecting Docker Engine.

  • CVE-2026-15793: Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
  • CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic. GHSA-qx3x-mv6r-52p6
  • CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the /tmp directory. GHSA-32pv-7hq5-qhwq
  • CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources. GHSA-g2h8-426c-7976
  • CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root. GHSA-388v-wmr2-g2v2

Packaging updates

Rootless

v29.6.1

Choose a tag to compare

@vvoland vvoland released this 26 Jun 12:29
docker-v29.6.1
8ec5ab3

29.6.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release includes fixes for multiple security vulnerabilities affecting Docker Engine.

  • A malicious image could supply a malicious /etc/passwd or /etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. GHSA-mjcv-p78q-w5fw, GHSA-jpcc-p29g-p8mq, GHSA-72x6-4j93-7w86
  • A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers. GHSA-7236-3392-c5c6

Bug fixes and enhancements

Packaging updates

v29.6.0

Choose a tag to compare

@vvoland vvoland released this 18 Jun 20:43
docker-v29.6.0
70eaf5e

29.6.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New

  • POST /containers/{id}/update now supports per-device blkio resource settings. moby/moby#52651
  • Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement query parameter for verbatim statement bodies.

Bug fixes and enhancements

  • docker image push now respects NO_COLOR. docker/cli#6957
  • containerd image store: Fix docker system prune to include unpacked image data when reporting reclaimed space. moby/moby#52905
  • Fix docker system df image size reporting to count only snapshots directly used by images. moby/moby#52901
  • Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. moby/moby#52698
  • Fix default BuildKit GC policy to prune reproducible cache types as intended. moby/moby#52814
  • Fix explicit file modes being filtered by the daemon umask, including COPY --chmod permissions. moby/moby#52892
  • Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests. moby/moby#52773
  • The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin. docker/cli#7029

Packaging updates

Networking

  • Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the nft command is not installed on the system. moby/moby#52820
  • Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports. moby/moby#52818
  • Fix a race condition in overlay network bulk sync that caused ~30s DNS resolution delays on newly joined swarm nodes. moby/moby#52862
  • Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the nft command instead. Users building dockerd from source can opt into linking against libnftables by building with the libnftables build tag. moby/moby#52886

Rootless

  • Silence the spurious warning "IPv4 forwarding is disabled". moby/moby#52742

Deprecations

  • The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. moby/moby#47427

client/0.5.0

Choose a tag to compare

@vvoland vvoland released this 18 Jun 19:36
client/v0.5.0
19e5ed7

0.5.0

Changelog

  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636

api/v1.55.0

Choose a tag to compare

@vvoland vvoland released this 18 Jun 19:16
api/v1.55.0
b6c53c2

1.55.0

Changelog

  • POST /containers/{id}/update now supports per-device blkio resource settingss. moby/moby#52651
  • The new GET /images/{name}/attestations endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in statement query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636
  • docs: clarify swarm join required fields. moby/moby#52763