Skip to content

[pull] main from containerd:main - #307

Open
pull[bot] wants to merge 1397 commits into
fahedouch:mainfrom
containerd:main
Open

[pull] main from containerd:main#307
pull[bot] wants to merge 1397 commits into
fahedouch:mainfrom
containerd:main

Conversation

@pull

@pull pull Bot commented May 10, 2025

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.1)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot added the ⤵️ pull label May 10, 2025
AkihiroSuda and others added 29 commits June 28, 2026 04:39
…tions/attest-build-provenance-4.1.1

build(deps): bump actions/attest-build-provenance from 4.1.0 to 4.1.1
…tions/cache-6.1.0

build(deps): bump actions/cache from 6.0.0 to 6.1.0
test: remove redundant test lock pre-check
Bumps the docker group with 1 update in the / directory: [github.com/docker/cli](https://github.com/docker/cli).


Updates `github.com/docker/cli` from 29.6.0+incompatible to 29.6.1+incompatible
- [Commits](docker/cli@v29.6.0...v29.6.1)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.6.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
…-a2be455989

build(deps): bump github.com/docker/cli from 29.6.0+incompatible to 29.6.1+incompatible in the docker group across 1 directory
Signed-off-by: immanuwell <pchpr.00@list.ru>
…eway

fix(network): match each gateway to its subnet for dual-stack
network create applied a single --ip-range to every subnet, so on a
dual-stack network the IPv4 range was checked against the IPv6 subnet
and creation failed with "no matching subnet". Accept --ip-range more
than once and match each range to the subnet that contains it, the same
way --gateway is handled.

Signed-off-by: Mayur Das <mayur.das@neevcloud.com>
Bumps [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) from 2.12.1 to 2.13.0.
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.12.1...v2.13.0)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/compose-spec/compose-go/v2-2.13.0

build(deps): bump github.com/compose-spec/compose-go/v2 from 2.12.1 to 2.13.0
Bumps [github.com/Microsoft/hcsshim](https://github.com/Microsoft/hcsshim) from 0.15.0-rc.2 to 0.15.0-rc.3.
- [Release notes](https://github.com/Microsoft/hcsshim/releases)
- [Commits](microsoft/hcsshim@v0.15.0-rc.2...v0.15.0-rc.3)

---
updated-dependencies:
- dependency-name: github.com/Microsoft/hcsshim
  dependency-version: 0.15.0-rc.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: immanuwell <pchpr.00@list.ru>
….com/Microsoft/hcsshim-0.15.0-rc.3

build(deps): bump github.com/Microsoft/hcsshim from 0.15.0-rc.2 to 0.15.0-rc.3
Assisted-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Bumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.18.6 to 1.18.7.
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.18.6...v1.18.7)

---
updated-dependencies:
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.18.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/klauspost/compress-1.18.7

build(deps): bump github.com/klauspost/compress from 1.18.6 to 1.18.7
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.2.0 to 7.3.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@f9f3042...53b7df9)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@0611638...96fe6ef)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.18.7 to 1.19.0.
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.18.7...v1.19.0)

---
updated-dependencies:
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 6.1.0 to 6.2.0.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](docker/metadata-action@80c7e94...dc80280)

---
updated-dependencies:
- dependency-name: docker/metadata-action
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@650006c...c99871d)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@d7f5e7f...bb05f3f)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/klauspost/compress-1.19.0

build(deps): bump github.com/klauspost/compress from 1.18.7 to 1.19.0
…cker/build-push-action-7.3.0

build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0
…cker/metadata-action-6.2.0

build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0
…cker/setup-buildx-action-4.2.0

build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
…cker/login-action-4.3.0

build(deps): bump docker/login-action from 4.2.0 to 4.3.0
dependabot Bot and others added 30 commits August 20, 2026 22:32
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@bb05f3f...37fe631)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/Microsoft/hcsshim](https://github.com/Microsoft/hcsshim) from 0.15.0-rc.3 to 0.15.0-rc.4.
- [Release notes](https://github.com/Microsoft/hcsshim/releases)
- [Commits](microsoft/hcsshim@v0.15.0-rc.3...v0.15.0-rc.4)

---
updated-dependencies:
- dependency-name: github.com/Microsoft/hcsshim
  dependency-version: 0.15.0-rc.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Hayato Kiwata <dev@haytok.jp>
….com/containerd/platforms-1.0.0-rc.5

build(deps): bump github.com/containerd/platforms from 1.0.0-rc.4 to 1.0.0-rc.5
….com/Microsoft/hcsshim-0.15.0-rc.4

build(deps): bump github.com/Microsoft/hcsshim from 0.15.0-rc.3 to 0.15.0-rc.4
…cker/setup-buildx-action-4.3.0

build(deps): bump docker/setup-buildx-action from 4.2.0 to 4.3.0
feat(push): support `--all-tags` to push all tags
Signed-off-by: Jiwoo Ahn <ikwydls1314@gmail.com>
fix(image): pin the image a container runs to its digest
fix(network): stop injecting ipRange into the CNI config
`nerdctl save -o FILE` and `nerdctl export -o FILE` open the output with O_CREATE|O_WRONLY
and no O_TRUNC. Writing a smaller archive over a bigger one therefore leaves the tail of
the bigger one past the end of the new archive.

A tar reader stops at the end-of-archive marker, so `nerdctl load` reads such a file
without complaining. What is wrong is the artifact: it is larger than the archive it is
supposed to hold, and the extra bytes belong to an unrelated image or container, which
shows up in anything that checksums the file, accounts for its size, or ships it
somewhere. `docker save` replaces the destination wholesale, writing through a temporary
file and renaming it.

Add O_TRUNC, so that `-o` replaces the file as a shell redirect does.

`pkg/healthcheck/log.go` opens a file with the same flags, but seeks to the end and
appends on purpose, so it is left alone.

Fixes #5159

Signed-off-by: Eugene Kalinin <e.v.kalinin@gmail.com>
Expand the Docker v29 view added in #5093 with `--tree`, matching
`docker image ls --tree`: the same IMAGE, ID, DISK USAGE, CONTENT SIZE and
EXTRA columns, plus one row per platform the image declares, prefixed with the
branch glyphs docker/cli uses. Like docker, a platform that an index lists but
that was never pulled is shown with zero sizes. The collapsed and the legacy
views keep describing only what is in the store, and so does EnsureAllContent,
which would otherwise reach out for platforms the user never asked for.

A platform row carries its own manifest digest as the ID, its own sizes, and
the "U" flag only when a container actually runs that platform. The image row
keeps aggregating its platforms and reuses the existing target-digest lookup,
so the default view is unchanged.

Matching a container to a platform is done on the full platform form, not on
the name the row displays: an index can carry several windows/amd64 manifests
that differ only by OSVersion, and keying on the displayed name would let a
container on one build flag all of them. The container label is normalized
first, since platforms.DefaultString does not normalize: on arm64 it carries a
variant while the manifest platform normalizes to a bare linux/arm64, and a raw
comparison would never match. The rows are sorted on that same full form, so
the ones that render identically keep a stable order.

Unlike docker/cli, which computes its column widths itself and separates the
images with a blank line, the rows go through a tabwriter shared with the
header, where a blank line would terminate the column block and misalign
every following group. The groups are therefore separated by the glyphs alone.

The flag combinations docker rejects in shouldUseTree are rejected here too,
with the same messages. They are validated in pkg/cmd/image, where the options
are consumed, so that library callers are covered as well: the tree branch
takes precedence over the formatter, so Tree together with Format used to
print unaligned rows with no header. The CLI validates too, so that the error
still surfaces before a containerd connection is attempted.

Also read the platform of a multi-platform image from its index descriptor
rather than from the image config. The config may be less specific: alpine
ships linux/arm/v6 and linux/arm/v7 manifests whose configs both declare a
bare "linux/arm", which normalizes to linux/arm/v7 and collapsed the two onto
a single key, dropping one platform. That also left it out of the aggregated
sizes of the default view.

The expected per-platform content sizes are declared in testutil, and the
integration test runs against docker as well, only diverging where docker
does: `docker pull` has no --all-platforms, and its message for the digests
conflict names its internal flag. DISK USAGE is only asserted to cover CONTENT
SIZE, because which platforms are unpacked depends on what the rest of the
suite did with the shared image store.

Closes #5005

Signed-off-by: Eugene Kalinin <e.v.kalinin@gmail.com>
feat(logging): add --log-file to persist nerdctl's own log
Signed-off-by: Aaron Paterson <apaterson@protonmail.com>
correct tmpfs path /var/lib/journal -> /var/log/journal
fix(image): truncate the output file of save and export
feat(image): add --tree flag to image list
- command-reference.md: complete the truncated word in the --rdt-class
  description ("container wit" -> "container with"), matching the flag's
  actual usage string in cmd/nerdctl/container/container_run.go.
- cosign.md: "capibility" -> "capability".
- gpu.md: "ouptut" -> "output".

Signed-off-by: MsfPablo <pablogarciacaceres5@gmail.com>
docs: fix typos in command reference, cosign and gpu docs
Bumps the containerd group with 1 update: [github.com/containerd/containerd/api](https://github.com/containerd/containerd).


Updates `github.com/containerd/containerd/api` from 1.12.0-beta.0 to 1.12.0-rc.0
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@api/v1.12.0-beta.0...api/v1.12.0-rc.0)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd/api
  dependency-version: 1.12.0-rc.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: containerd
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Vladislav Lapin <51929896+loglapa@users.noreply.github.com>
…nerd-222ddf8d52

build(deps): bump github.com/containerd/containerd/api from 1.12.0-beta.0 to 1.12.0-rc.0 in the containerd group
[healthcheck] optimize: reduce unnecessary function calls
ci: Print daemon logs after integration test failures
Bumps [github.com/containerd/go-cni](https://github.com/containerd/go-cni) from 1.1.13 to 1.1.14.
- [Release notes](https://github.com/containerd/go-cni/releases)
- [Commits](containerd/go-cni@v1.1.13...v1.1.14)

---
updated-dependencies:
- dependency-name: github.com/containerd/go-cni
  dependency-version: 1.1.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/containernetworking/cni](https://github.com/containernetworking/cni) from 1.3.0 to 1.3.1.
- [Release notes](https://github.com/containernetworking/cni/releases)
- [Commits](containernetworking/cni@v1.3.0...v1.3.1)

---
updated-dependencies:
- dependency-name: github.com/containernetworking/cni
  dependency-version: 1.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/containernetworking/cni-1.3.1

build(deps): bump github.com/containernetworking/cni from 1.3.0 to 1.3.1
….com/containerd/go-cni-1.1.14

build(deps): bump github.com/containerd/go-cni from 1.1.13 to 1.1.14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.