Releases: moby/moby
Release list
v29.7.2
29.7.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Fix
docker service createanddocker service updatepanicking when the same environment variable is passed more than once. docker/cli#7145 - Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets, as produced by some image builders. moby/moby#53305
- Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and
docker cpto fail on older Linux kernels when applying file permissions, including for device nodes. moby/moby#53305
Packaging updates
- Update BuildKit to v0.32.2. moby/moby#53300
Networking
- Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon. moby/moby#53303
v29.7.1
29.7.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries. moby/moby#53260
- Fix a regression where the
CopyToContainerrejects container paths that traverse absolute symlinks, such as/var/run->/run. moby/moby#53261
v29.7.0
29.7.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
- Add an experimental
embedded-containerdfeature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898 - Mount type
imageis no longer experimental. moby/moby#52998 - Add the
default-stop-timeoutdaemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146
Security
This release includes a fix for a security vulnerability affecting Docker Engine and related components.
- Update github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h. moby/moby#53247, docker/cli#7139
Networking
- Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network. moby/moby#53237
- Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022
Rootless
- Keep the cgroup mount for containers with
--net=host. moby/moby#52318
Bug fixes and enhancements
- Add shell completion for
--filternames and known values todocker service ls,docker service ps, anddocker node ps. docker/cli#7124 - containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
- To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
- Fix
docker cp -ausing the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084 - Fix
docker cpfrom a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory. moby/moby#53123 - Fix
docker statsreporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101 - Fix
docker statsreporting empty network stats for running Windows containers when using the containerd runtime. moby/moby#53219 - Fix a typo in the
docker create --pullflag description. docker/cli#7103 - Fix Swarm service updates failing due to "file exists" errors when a VIP IP alias already exists on the LB endpoint interface. moby/moby#51657
- Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node. moby/moby#53212
- Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
- Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
- Suppress the “No such container” error when
docker rm --forcesucceeds for a nonexistent container. docker/cli#7110
Packaging updates
- Update Go runtime to 1.26.5. docker/cli#7087
- Update BuildKit to v0.32.0. moby/moby#53234
- Update containerd (static binaries) to v2.3.3. moby/moby#53050
- Update runc (in static binaries) to v1.4.3. moby/moby#50960
client/v0.5.1
0.5.1
Changelog
- client/pkg/jsonmessage: Display: fix godoc link. moby/moby#53070
- client: ServiceCreate, ServiceUpdate: fix duplicate and 'unkown' platforms. moby/moby#53012
- client: ServiceInspect, ContainerCommit: omit optional query args if not set. moby/moby#53010
- golangci-lint: enable perfsprint linter. moby/moby#53016
v29.7.0-rc.1
29.7.0-rc.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
- Add an experimental
embedded-containerdfeature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898
Bug fixes and enhancements
- Add the
default-stop-timeoutdaemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146 - containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
- To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
- Fix
docker cp -ausing the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084 - Fix
docker statsreporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101 - Fix a typo in the
docker create --pullflag description. docker/cli#7103 - Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
- Mount type
imageis no longer experimental. moby/moby#52998 - Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
- Suppress the “No such container” error when
docker rm --forcesucceeds for a nonexistent container. docker/cli#7110 - Update Go runtime to 1.26.5. docker/cli#7087
Packaging updates
- Update BuildKit to v0.32.0-rc2. moby/moby#53209
- Update containerd (static binaries) to v2.3.3. moby/moby#53050
- Update runc (in static binaries) to v1.4.3. moby/moby#50960
Networking
- Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022
Rootless
- Keep the cgroup mount for containers with
--net=host. moby/moby#52318
v29.6.2
29.6.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release includes fixes for multiple security vulnerabilities affecting Docker Engine.
- CVE-2026-15793: Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
- CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic. GHSA-qx3x-mv6r-52p6
- CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the
/tmpdirectory. GHSA-32pv-7hq5-qhwq - CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources. GHSA-g2h8-426c-7976
- CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root. GHSA-388v-wmr2-g2v2
Packaging updates
- Update containerd (static binaries) to v2.2.6. moby/moby#53051
- Update Go runtime to 1.26.5. moby/moby#53027
Rootless
- Update RootlessKit to v3.0.2. moby/moby#53054
v29.6.1
29.6.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release includes fixes for multiple security vulnerabilities affecting Docker Engine.
- A malicious image could supply a malicious
/etc/passwdor/etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. GHSA-mjcv-p78q-w5fw, GHSA-jpcc-p29g-p8mq, GHSA-72x6-4j93-7w86 - A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers. GHSA-7236-3392-c5c6
Bug fixes and enhancements
- Update containerd (static binaries) to v2.2.5. moby/moby#52950
Packaging updates
- Update BuildKit to v0.31.1. moby/moby#52954
v29.6.0
29.6.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
POST /containers/{id}/updatenow supports per-device blkio resource settings. moby/moby#52651- Add
GET /images/{name}/attestationsendpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement query parameter for verbatim statement bodies.
Bug fixes and enhancements
docker image pushnow respectsNO_COLOR. docker/cli#6957- containerd image store: Fix
docker system pruneto include unpacked image data when reporting reclaimed space. moby/moby#52905 - Fix
docker system dfimage size reporting to count only snapshots directly used by images. moby/moby#52901 - Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. moby/moby#52698
- Fix default BuildKit GC policy to prune reproducible cache types as intended. moby/moby#52814
- Fix explicit file modes being filtered by the daemon umask, including
COPY --chmodpermissions. moby/moby#52892 - Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests. moby/moby#52773
- The
--passwordflag ondocker loginnow accepts-to pass the password through STDIN as alternative to--password-stdin. docker/cli#7029
Packaging updates
- Update runc (in static binaries) to v1.3.6. moby/moby#52883
- Update BuildKit to v0.31.0. moby/moby#52904
Networking
- Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the
nftcommand is not installed on the system. moby/moby#52820 - Don't publish container ports on host ports listed in
net.ipv4.ip_local_reserved_portswhen dynamically allocating ports. moby/moby#52818 - Fix a race condition in overlay network bulk sync that caused ~30s DNS resolution delays on newly joined swarm nodes. moby/moby#52862
- Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the
nftcommand instead. Users building dockerd from source can opt into linking against libnftables by building with thelibnftablesbuild tag. moby/moby#52886
Rootless
- Silence the spurious warning "IPv4 forwarding is disabled". moby/moby#52742
Deprecations
- The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. moby/moby#47427
client/0.5.0
0.5.0
Changelog
- The new
GET /images/{name}/attestationsendpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-instatementquery parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636
api/v1.55.0
1.55.0
Changelog
POST /containers/{id}/updatenow supports per-device blkio resource settingss. moby/moby#52651- The new
GET /images/{name}/attestationsendpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-instatementquery parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. moby/moby#52636 - docs: clarify swarm join required fields. moby/moby#52763